From 3194941f93f9e814b5e233ff20c59635bda2fb51 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 11 Jun 2025 18:55:27 -0500 Subject: [PATCH 001/124] Fix jude --- flake.lock | 62 +++++++++---------- home/hosts/jude/default.nix | 1 - hosts/jude/default.nix | 37 ++++++++---- modules/hm/default.nix | 1 - modules/hm/sway.nix | 115 ------------------------------------ modules/nixos/default.nix | 1 - modules/nixos/gnome.nix | 6 +- modules/nixos/kde.nix | 8 +-- modules/nixos/sway.nix | 44 -------------- 9 files changed, 62 insertions(+), 213 deletions(-) delete mode 100644 modules/hm/sway.nix delete mode 100644 modules/nixos/sway.nix diff --git a/flake.lock b/flake.lock index 58b8dae..4ff927e 100644 --- a/flake.lock +++ b/flake.lock @@ -31,11 +31,11 @@ "nixpkgs-unstable": "nixpkgs-unstable" }, "locked": { - "lastModified": 1748187031, - "narHash": "sha256-F4zdOfeg0xjEnvFjlHvoMmdmh/FxK1qIsZyscnGDgA0=", + "lastModified": 1749652690, + "narHash": "sha256-qLwBEXlGY2pLNPhPNpeOE0DNC1luovTYE3ZDPMyMPXc=", "owner": "fort-nix", "repo": "nix-bitcoin", - "rev": "a06d1d8118865af14a9187e7d1a7a141dd89af74", + "rev": "ac1344fb6d91e2af219803eaaa67d1d974666156", "type": "github" }, "original": { @@ -187,11 +187,11 @@ ] }, "locked": { - "lastModified": 1743550720, - "narHash": "sha256-hIshGgKZCgWh6AYJpJmRgFdR3WUbkY04o82X05xqQiY=", + "lastModified": 1749398372, + "narHash": "sha256-tYBdgS56eXYaWVW3fsnPQ/nFlgWi/Z2Ymhyu21zVM98=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "c621e8422220273271f52058f618c94e405bb0f5", + "rev": "9305fe4e5c2a6fcf5ba6a3ff155720fbe4076569", "type": "github" }, "original": { @@ -321,11 +321,11 @@ ] }, "locked": { - "lastModified": 1749526396, - "narHash": "sha256-UL9F76abAk87llXOrcQRjhd5OaOclUd6MIltsqcUZmo=", + "lastModified": 1749657191, + "narHash": "sha256-QLilaHuhGxiwhgceDWESj9gFcKIdEp7+9lRqNGpN8S4=", "owner": "nix-community", "repo": "home-manager", - "rev": "427c96044f11a5da50faf6adaf38c9fa47e6d044", + "rev": "faeab32528a9360e9577ff4082de2d35c6bbe1ce", "type": "github" }, "original": { @@ -363,11 +363,11 @@ "nixpkgs": "nixpkgs_2" }, "locked": { - "lastModified": 1747372754, - "narHash": "sha256-2Y53NGIX2vxfie1rOW0Qb86vjRZ7ngizoo+bnXU9D9k=", + "lastModified": 1749636823, + "narHash": "sha256-WUaIlOlPLyPgz9be7fqWJA5iG6rHcGRtLERSCfUDne4=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "80479b6ec16fefd9c1db3ea13aeb038c60530f46", + "rev": "623c56286de5a3193aa38891a6991b28f9bab056", "type": "github" }, "original": { @@ -457,16 +457,16 @@ }, "nixpkgs": { "locked": { - "lastModified": 1748037224, - "narHash": "sha256-92vihpZr6dwEMV6g98M5kHZIttrWahb9iRPBm1atcPk=", + "lastModified": 1749494155, + "narHash": "sha256-FG4DEYBpROupu758beabUk9lhrblSf5hnv84v1TLqMc=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "f09dede81861f3a83f7f06641ead34f02f37597f", + "rev": "88331c17ba434359491e8d5889cce872464052c2", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-24.11", + "ref": "nixos-25.05", "repo": "nixpkgs", "type": "github" } @@ -518,11 +518,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1747958103, - "narHash": "sha256-qmmFCrfBwSHoWw7cVK4Aj+fns+c54EBP8cGqp/yK410=", + "lastModified": 1749558678, + "narHash": "sha256-DUVAe8E2X2QM0dAnTGlTiqemMqUMMyIeCH7UeNo0g64=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "fe51d34885f7b5e3e7b59572796e1bcb427eccb1", + "rev": "a12f3a99614894502e73eb816e9e076b0ab05730", "type": "github" }, "original": { @@ -621,11 +621,11 @@ "systems": "systems_4" }, "locked": { - "lastModified": 1749496904, - "narHash": "sha256-eNDMzrcDBOprdJs7DpMOJfCEcxribxDJP2OjozSC3Wo=", + "lastModified": 1749644591, + "narHash": "sha256-v72hZJvAA78+LWohTzTwk/OnzsNxbkoTM+G7+iXwdl0=", "owner": "nix-community", "repo": "nixvim", - "rev": "e0b3d8bc3a0ab5a7cc0792c7705e92f9c5c598f3", + "rev": "64f0d3c86a7894cad9b09bb1015375ffb9949d70", "type": "github" }, "original": { @@ -642,11 +642,11 @@ "treefmt-nix": "treefmt-nix" }, "locked": { - "lastModified": 1749566933, - "narHash": "sha256-rolwj4dzqfzFMG3VGEN7zKwGTBd0XAKcvOTTEOre3XY=", + "lastModified": 1749670360, + "narHash": "sha256-YmJ5Zffr6tJID0nA3XkQaoeDLFhOZKBtvZl31jXsqQg=", "owner": "nix-community", "repo": "NUR", - "rev": "28532113cfab3f76c3a80f04ef38dca164d7b819", + "rev": "74f88e0178318b15c3c6d8832c681cc4e72c3d92", "type": "github" }, "original": { @@ -665,11 +665,11 @@ ] }, "locked": { - "lastModified": 1748298102, - "narHash": "sha256-PP11GVwUt7F4ZZi5A5+99isuq39C59CKc5u5yVisU/U=", + "lastModified": 1749531675, + "narHash": "sha256-UB8Mc88rW9frjpJ1Fj2ro7f07Gg8dX3uVXvMXnFR4CE=", "owner": "NuschtOS", "repo": "search", - "rev": "f8a1c221afb8b4c642ed11ac5ee6746b0fe1d32f", + "rev": "4029d450d0266909ee52775849b7da54e79b328e", "type": "github" }, "original": { @@ -869,11 +869,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1749521131, - "narHash": "sha256-ezZ15tLA2L+rmtn39dKLFW/UM2xlksC61V12blulpjE=", + "lastModified": 1749607503, + "narHash": "sha256-ou8BXMfitXrT5dAuxcx3g2kIg3akNe8TdPmxaPlf5UU=", "owner": "nix-community", "repo": "nix-vscode-extensions", - "rev": "299b2aa650d32310153746135b6a84a6c4de9c21", + "rev": "06a79e7e0edfcbe28b3e60c78d91c9f75998a8f3", "type": "github" }, "original": { diff --git a/home/hosts/jude/default.nix b/home/hosts/jude/default.nix index bdce016..3b6e8c8 100644 --- a/home/hosts/jude/default.nix +++ b/home/hosts/jude/default.nix @@ -4,7 +4,6 @@ greg = { development = true; gui = true; - sway = false; gnome = false; vscodium = true; zed = true; diff --git a/hosts/jude/default.nix b/hosts/jude/default.nix index cef3e40..855ad9f 100644 --- a/hosts/jude/default.nix +++ b/hosts/jude/default.nix @@ -19,7 +19,6 @@ greg = { tailscale.enable = true; - sway.enable = false; gnome.enable = true; kde.enable = false; kubernetes.enable = true; @@ -73,16 +72,34 @@ ]; hardware = { - nvidia = { - package = config.boot.kernelPackages.nvidiaPackages.vulkan_beta; - modesetting.enable = true; - powerManagement = { - enable = false; - finegrained = false; + nvidia = + let + gpl_symbols_linux_615_patch = pkgs.fetchpatch { + url = "https://github.com/CachyOS/kernel-patches/raw/914aea4298e3744beddad09f3d2773d71839b182/6.15/misc/nvidia/0003-Workaround-nv_vm_flags_-calling-GPL-only-code.patch"; + hash = "sha256-YOTAvONchPPSVDP9eJ9236pAPtxYK5nAePNtm2dlvb4="; + stripLen = 1; + extraPrefix = "kernel/"; + }; + in + { + #package = config.boot.kernelPackages.nvidiaPackages.vulkan_beta; + package = config.boot.kernelPackages.nvidiaPackages.mkDriver { + version = "575.57.08"; + openSha256 = "sha256-DOJw73sjhQoy+5R0GHGnUddE6xaXb/z/Ihq3BKBf+lg="; + sha256_64bit = "sha256-KqcB2sGAp7IKbleMzNkB3tjUTlfWBYDwj50o3R//xvI="; + settingsSha256 = "sha256-AIeeDXFEo9VEKCgXnY3QvrW5iWZeIVg4LBCeRtMs5Io="; + persistencedSha256 = "sha256-Len7Va4HYp5r3wMpAhL4VsPu5S0JOshPFywbO7vYnGo="; + usePersistenced = true; + patches = [ gpl_symbols_linux_615_patch ]; + }; + modesetting.enable = true; + powerManagement = { + enable = false; + finegrained = false; + }; + nvidiaSettings = true; + open = true; }; - nvidiaSettings = true; - open = true; - }; system76 = { firmware-daemon.enable = true; #kernel-modules.enable = true; diff --git a/modules/hm/default.nix b/modules/hm/default.nix index c2b67e8..86ddda1 100644 --- a/modules/hm/default.nix +++ b/modules/hm/default.nix @@ -6,7 +6,6 @@ ./gnome.nix ./gui.nix ./python.nix - ./sway.nix ./vscodium.nix ./xonsh.nix ./zed.nix diff --git a/modules/hm/sway.nix b/modules/hm/sway.nix deleted file mode 100644 index 9a8112a..0000000 --- a/modules/hm/sway.nix +++ /dev/null @@ -1,115 +0,0 @@ -{ - config, - pkgs, - lib, - ... -}: - -let - cfg = config.greg.sway; - file_browser = { - pkg = pkgs.krusader; - path = "${pkgs.krusader}/bin/krusader"; - }; - term = "${pkgs.alacritty}/bin/alacritty"; - msg = "${pkgs.sway}/bin/swaymsg"; - sleep = "${pkgs.coreutils}/bin/sleep"; - workstation1 = pkgs.writeScriptBin "workstation1" ( - builtins.concatStringsSep "\n" [ - "${msg} \"workspace 1 ; exec ${pkgs.firefox}/bin/firefox ; split horizontal ; exec ${pkgs.element-desktop}/bin/element-desktop \"" - "${sleep} 1" - "${msg} '[app_id=\"firefox\"]' move left" - "${msg} '[instance=\"element\"]' \"layout tabbed ; exec ${term} \"" - "${msg} '[app_id=\"firefox\"]' move left" - "${sleep} 0.3" - "${msg} '[app_id=\"Alacritty\" workspace=\"1\"]' move right" - "${msg} '[app_id=\"firefox\"]' resize grow width 300 px" - ] - ); - workstation2 = pkgs.writeScriptBin "workstation2" ( - builtins.concatStringsSep "\n" [ - "${sleep} 5" - "${msg} \"workspace 2 ; exec ${term} ; layout tabbed\"" - ] - ); -in -{ - options.greg.sway = lib.mkEnableOption "Enable Sway support and settings"; - - config = ( - lib.mkIf cfg { - programs.swaylock.enable = true; - - wayland.windowManager.sway = - let - mod = config.wayland.windowManager.sway.config.modifier; - in - { - enable = true; - config = rec { - #fonts.size = 10.0; - keybindings = lib.mkOptionDefault { - "Mod4+l" = "exec ${pkgs.swaylock}/bin/swaylock -c 000000"; - "Mod4+h" = "exec ${pkgs.qpwgraph}/bin/qpwgraph -x /home/greg/sound/headphones.qpwgraph -m"; - "Mod4+m" = "exec ${pkgs.qpwgraph}/bin/qpwgraph -x /home/greg/sound/monitor.qpwgraph -m"; - "Mod4+b" = "exec ${pkgs.qpwgraph}/bin/qpwgraph -x /home/greg/sound/both.qpwgraph -m"; - - "${mod}+Shift+Return" = file_browser.path; - }; - modifier = "Mod1"; - output = { - "Samsung Electric Company S24E650 H4ZN600985" = { - mode = "1920x1200"; - transform = "90"; - pos = "0 0"; - }; - "ViewSonic Corporation VA2252 Series VMT201800925" = { - mode = "1920x1080"; - pos = "200 1920"; - }; - }; - terminal = term; - startup = [ - { command = "${workstation1}/bin/workstation1"; } - { command = "${workstation2}/bin/workstation2"; } - ]; - }; - extraOptions = [ "--unsupported-gpu" ]; - extraSessionCommands = '' - export WLR_NO_HARDWARE_CURSORS=1 - ''; - systemd.enable = true; - wrapperFeatures = { - base = true; - gtk = true; - }; - }; - - home.pointerCursor = { - name = "Adwaita"; - package = pkgs.gnome.adwaita-icon-theme; - size = 12; - x11 = { - enable = true; - defaultCursor = "Adwaita"; - }; - }; - - home.packages = with pkgs; [ - arj - dpkg - kate - kget - krename - file_browser.pkg - p7zip - plocate - rpm - qpwgraph - xorg.xev - xorg.xmodmap - xxdiff - ]; - } - ); -} diff --git a/modules/nixos/default.nix b/modules/nixos/default.nix index 805ff5b..d1185e0 100644 --- a/modules/nixos/default.nix +++ b/modules/nixos/default.nix @@ -20,7 +20,6 @@ ./remote-builder.nix ./router.nix ./rpi4.nix - ./sway.nix ./syncthing.nix ./tailscale.nix ./vmdev.nix diff --git a/modules/nixos/gnome.nix b/modules/nixos/gnome.nix index dd61bcb..209af52 100644 --- a/modules/nixos/gnome.nix +++ b/modules/nixos/gnome.nix @@ -23,10 +23,10 @@ with lib; # Trackpad support libinput.enable = true; + displayManager.gdm.enable = true; + desktopManager.gnome.enable = true; + xserver = { - enable = true; - displayManager.gdm.enable = true; - desktopManager.gnome.enable = true; xkb.layout = "us"; }; diff --git a/modules/nixos/kde.nix b/modules/nixos/kde.nix index d6f37bd..7fcf7b7 100644 --- a/modules/nixos/kde.nix +++ b/modules/nixos/kde.nix @@ -24,12 +24,6 @@ with lib; systemd.services.bluetooth.requiredBy = [ "multi-user.target" ]; services = { - xserver = { - enable = true; - xkb.layout = "us"; - # Trackpad support - }; - libinput.enable = true; blueman.enable = true; @@ -49,7 +43,7 @@ with lib; }); programs.dconf.enable = true; - programs.sway.enable = true; # Gives us Wayland + xdg.portal = { enable = true; wlr.enable = true; # Enables screen sharing in Wayland diff --git a/modules/nixos/sway.nix b/modules/nixos/sway.nix deleted file mode 100644 index 6ab8e5d..0000000 --- a/modules/nixos/sway.nix +++ /dev/null @@ -1,44 +0,0 @@ -{ config, lib, ... }: - -let - cfg = config.greg.sway; - -in -with lib; -{ - options = { - greg.sway.enable = mkEnableOption "Enable my default Gnome3 setup"; - }; - - config = mkIf cfg.enable { - services = { - accounts-daemon.enable = true; - - pipewire = { - enable = true; - alsa.enable = true; - audio.enable = true; - jack.enable = true; - pulse.enable = true; - wireplumber.enable = true; - }; - - xserver = { - enable = true; - displayManager.gdm = { - enable = true; - autoSuspend = false; - banner = "Welcome to Greg's JUDE machine. Do I know you?"; - wayland = true; - }; - xkb.layout = "us"; - }; - }; - - programs.sway = { - enable = true; # Will be enabled through home-manager - wrapperFeatures.gtk = true; - }; - security.pam.services.swaylock = { }; - }; -} From 963757171af7e447db85cdcaf4ea986bc1c890b8 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 11 Jun 2025 20:03:18 -0500 Subject: [PATCH 002/124] New disks for vm-gitlab --- hosts/vm-gitlab/hardware-configuration.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hosts/vm-gitlab/hardware-configuration.nix b/hosts/vm-gitlab/hardware-configuration.nix index a945d9f..ae1216c 100644 --- a/hosts/vm-gitlab/hardware-configuration.nix +++ b/hosts/vm-gitlab/hardware-configuration.nix @@ -34,12 +34,12 @@ }; fileSystems."/" = { - device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb"; + device = "/dev/disk/by-uuid/1fdbe86e-ce6f-4af3-a876-aec35731adab"; fsType = "ext4"; }; fileSystems."/boot" = { - device = "/dev/disk/by-uuid/7115-EFA6"; + device = "/dev/disk/by-uuid/1E6A-C3BB"; fsType = "vfat"; options = [ "fmask=0077" From e13bee750cf969f550c245d0cd26226ab16aabf2 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 11 Jun 2025 21:29:20 -0500 Subject: [PATCH 003/124] Make gitlab use remote postgres --- hosts/vm-gitlab/default.nix | 101 +++++++++++++-------------------- secrets/gitlab/db-password.age | Bin 0 -> 2115 bytes secrets/secrets.nix | 1 + 3 files changed, 40 insertions(+), 62 deletions(-) create mode 100644 secrets/gitlab/db-password.age diff --git a/hosts/vm-gitlab/default.nix b/hosts/vm-gitlab/default.nix index 0c4a31d..266e281 100644 --- a/hosts/vm-gitlab/default.nix +++ b/hosts/vm-gitlab/default.nix @@ -33,6 +33,7 @@ in gitlab-secret = cfg "secret"; gitlab-otp = cfg "otp"; gitlab-db = cfg "db"; + gitlab-db-password = cfg "db-password"; gitlab-jws = cfg "jws"; gitlab-key = cfg "key"; gitlab-cert = cfg "cert"; @@ -105,9 +106,11 @@ in keepTime = 288; startAt = [ "03:00" ]; }; - host = "src.thehellings.com"; - https = true; - port = 443; + databaseHost = "postgres.kubernetes"; + databaseName = "gitlab"; + databaseUsername = "gitlab"; + databasePasswordFile = config.age.secrets.gitlab-db-password.path; + databaseCreateLocally = false; extraConfig = { gitlab = { trustedProxies = [ @@ -115,37 +118,6 @@ in "100.115.57.8/32" # Public server's IP ]; }; - }; - initialRootEmail = "greg@thehellings.com"; - initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password"; - pages = { - enable = true; - settings.pages-domain = "pages.thehellings.com"; - }; - puma = { - threadsMax = 6; - threadsMin = 2; - workers = 6; - }; - redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}"; - registry = { - enable = true; - certFile = config.age.secrets.gitlab-cert.path; - keyFile = config.age.secrets.gitlab-key.path; - externalAddress = "registry.thehellings.com"; - externalPort = 443; - }; - secrets = { - activeRecordDeterministicKeyFile = config.age.secrets.gitlab-deterministic-key.path; - activeRecordPrimaryKeyFile = config.age.secrets.gitlab-primary-key.path; - activeRecordSaltFile = config.age.secrets.gitlab-salt.path; - dbFile = config.age.secrets.gitlab-db.path; - jwsFile = config.age.secrets.gitlab-jws.path; - otpFile = config.age.secrets.gitlab-otp.path; - secretFile = config.age.secrets.gitlab-secret.path; - }; - - extraConfig = { object_store = { enabled = true; proxy_download = true; # Tell them to reach out to object storage themselves! @@ -182,6 +154,37 @@ in ); }; }; + host = "src.thehellings.com"; + https = true; + initialRootEmail = "greg@thehellings.com"; + initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password"; + pages = { + enable = true; + settings.pages-domain = "pages.thehellings.com"; + }; + port = 443; + puma = { + threadsMax = 6; + threadsMin = 2; + workers = 6; + }; + redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}"; + registry = { + enable = true; + certFile = config.age.secrets.gitlab-cert.path; + keyFile = config.age.secrets.gitlab-key.path; + externalAddress = "registry.thehellings.com"; + externalPort = 443; + }; + secrets = { + activeRecordDeterministicKeyFile = config.age.secrets.gitlab-deterministic-key.path; + activeRecordPrimaryKeyFile = config.age.secrets.gitlab-primary-key.path; + activeRecordSaltFile = config.age.secrets.gitlab-salt.path; + dbFile = config.age.secrets.gitlab-db.path; + jwsFile = config.age.secrets.gitlab-jws.path; + otpFile = config.age.secrets.gitlab-otp.path; + secretFile = config.age.secrets.gitlab-secret.path; + }; }; nginx = { @@ -206,42 +209,16 @@ in }; }; - logrotate = { - enable = true; - settings = { - "/var/lib/postgresql/*/log/*.log" = { - enable = true; - compress = true; - compresscmd = "${pkgs.xz}/bin/xz"; - }; - }; - }; - openssh.enable = true; - postgresql = { - enable = true; - checkConfig = true; - ensureDatabases = [ "gitlab" ]; - ensureUsers = [ - { - name = "gitlab"; - ensureDBOwnership = true; - } - ]; - settings = { - log_connections = true; - log_statement = "all"; - logging_collector = true; - log_filename = "postgresql.log"; - }; - }; + postgresql.enable = true; qemuGuest.enable = true; redis.servers.gitlab = { enable = true; }; + resolved.enable = true; }; diff --git a/secrets/gitlab/db-password.age b/secrets/gitlab/db-password.age new file mode 100644 index 0000000000000000000000000000000000000000..2deed6af3191bdb6abf26392f37657e4daf0a679 GIT binary patch literal 2115 zcmZYAIm`5H6$fw&3z;uq8?mqmx7oKw-XxPu_L*#x#l~!tOxBs~iG_ltg4jPcB9vTH+S!U$FIZSO^?iSW-*wJ)&i_Pt_Lj9tzdgo#*M76>b7)2mZ{Grjp?J$u zlpqiWAn_?G7l1$I1xke86p>9Yv}@qj@YdQ3nctPND^$xQS_7ensi6-mW?>TS&kH6O z9C^mhTHdip1agt(AL|77I0A17U2k{!z1D3)<17GPJZ!tf&VfSXSWA?6>W*vcXlQ}4 zSRI?OXwTVkbFAZV7^OWA&{CX^fl8lrN01~rQ9*A$F}ZV#!lR-ngFtjw5q_^V=jL+D zfl^y zaD#3VL$`w>U4+|MQ@$rA@3la=Tk!&nL_cMi=DE<8-e|?rlj9XZ$Jt1q{x&DGe({iE zGOWH#4k0V#Zmyss(uRtx>V#PH(<1Q>aZEtz+KRaEX`8d+`v)xwP}XMwryKLWBA2R> zJw1Lsw12cIq^u%rSK$^ZZ5sqwCQ%6*9LNgJ7Di-g>2h+apsVQi>LswbyHOW83a7f5 z6M#oQPCxwHYK(2i0=q=4B9W=Hc#@RTl$-e^*)u9lf|mNFj^GR0pH8Rcyi|wv-ZAi_ zRZcGX41AF{(YRM6HSWBbUd-{t8QOihMrTF)ps{9gLvkQ_3WPujLo@VohphM%JPP_s z?}a*Zosrgwp{}uCg^cYUGM8ypdqsT9uS$u#@2P6(Rr-+vLDyTQmSI?7QoohHL*ZzV_-J#xvO;!-|T9SJ+3RgdY z#4;Oa!Oiorybij#Uj{Fe=FWXTCA8amgbA#aW);?|nWM;hm5ObdJf!F*fW9T_#=wIu zg}3byv@7$Vo3~boim=Y$2ASF+fLT)VO*m~Y(&`z#AKwyOyJWUHyw_mJ8`K=|QenLo z4#GiKRT{a44sr$bjq{XnaCl;^#2#y&5{lKw52`|10dC)eWHAP+#1-z2-jg`LhLTp# z{KeN|4!I=!lhxmAMhy`g3sB=iJ(Ia>xt(DXm0veWLkfgka?%d7gx?(? z+(q`#a|f)O(!Gx5#Uh>2?2&D z207N^xmcq)0X^LuM6+;ggl5UWK6MNly_cX_4I>aE5z|MlGzRahK{&@_fStGY6Nj zK2isHb(3`Ao}LqGA8PB`#((6%<2ZrEt9y-rQA;0#%>v)aa#FW`5d}ULV-N)1?;!e%?| zJQ$o7X4uTmVDhWGdBwvtJX{d$ppg%{k}fV-!V-Ees+E*y&2bb^Q_j~L$vHtsU7B8d zR59&-*f%_Tpe_rD5XXr29^*!!;L#H9XD6|iu~N`GwL45n38Z+ruzmMRqo^aQN%i#A zcI;OUdorFPxYn!{F6Vm!p{w({9hxeSOK^C5djr_6YFoSW?bdosBVUE?{UY#pemOqY zPQ`CA_zGb{jardC{O{8*fA{-OfB4I1Km5*jJ>c8mpT7FF;PW5->+hfc;Gh5g;upXE t3izL|fANj)|M&LCf6Ra5eoC(F_kQxTFUP<6?B~Dz(w~(d|Mgd&{ttB+v339e literal 0 HcmV?d00001 diff --git a/secrets/secrets.nix b/secrets/secrets.nix index 4e09c95..0282f14 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -87,6 +87,7 @@ in "gitlab/secret.age".publicKeys = everyone; "gitlab/otp.age".publicKeys = everyone; "gitlab/db.age".publicKeys = everyone; + "gitlab/db-password.age".publicKeys = everyone; "gitlab/jws.age".publicKeys = everyone; # openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.crt -days 365 -nodes -subj '/CN=issuer' # Then pipe the resulting files to agenix -e From eddbf9292f32c19888af582b45ee26759831c613 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 11 Jun 2025 22:57:09 -0500 Subject: [PATCH 004/124] Fix gitlab. Again --- hosts/linode/git.nix | 6 ++--- hosts/vm-gitlab/default.nix | 53 ++++++++++++++----------------------- modules/nix-conf.nix | 6 ++--- 3 files changed, 25 insertions(+), 40 deletions(-) diff --git a/hosts/linode/git.nix b/hosts/linode/git.nix index fdb2b41..e92d052 100644 --- a/hosts/linode/git.nix +++ b/hosts/linode/git.nix @@ -6,7 +6,7 @@ let in { greg.proxies."${srcDomain}" = { - target = "http://git.thehellings.lan"; + target = "http://vm-gitlab.shire-zebra.ts.net"; ssl = true; genAliases = false; extraConfig = '' @@ -16,7 +16,7 @@ in ''; }; greg.proxies."registry.thehellings.com" = { - target = "https://registry.thehellings.lan:5000"; + target = "https://vm-gitlab.shire-zebra.ts.net:5000"; ssl = true; genAliases = false; extraConfig = "client_max_body_size 25000m;"; @@ -44,7 +44,7 @@ in " bind *:${toString sshPort}" " timeout client 1h" " mode tcp" - " server git-thehellings-lan git.thehellings.lan:22" + " server git-thehellings-lan vm-gitlab.shire-zebra.ts.net:22" ]; }; } diff --git a/hosts/vm-gitlab/default.nix b/hosts/vm-gitlab/default.nix index 266e281..c39c78b 100644 --- a/hosts/vm-gitlab/default.nix +++ b/hosts/vm-gitlab/default.nix @@ -11,12 +11,10 @@ let registryPort = 5000; - vpnIp = "100.91.131.66"; - containerIp = "192.168.200.2"; + vpnIp = "100.117.28.111"; in { imports = [ - # Include the results of the hardware scan. ./hardware-configuration.nix ]; @@ -55,30 +53,12 @@ in }; }; - greg.proxies = - let - t = { - target = "http://unix:/run/gitlab/gitlab-workhorse.socket"; - extraConfig = '' - proxy_set_header X-Forwarded-Proto https; - proxy_set_header X-Forwarded-Ssl on; - client_max_body_size 10000m; - ''; - }; - in - { - "${containerIp}" = t; - "${vpnIp}" = t; - "git.thehellings.lan" = t; - }; - - greg.backup.jobs.nas-backup = { - src = "/var/gitlab/state/backup/"; - dest = "gitlab"; - id = "container-gitlab"; - }; - greg = { + backup.jobs.nas-backup = { + src = "/var/gitlab/state/backup/"; + dest = "gitlab"; + id = "container-gitlab"; + }; home = true; tailscale.enable = true; }; @@ -96,7 +76,7 @@ in cron = { enable = true; systemCronJobs = [ - "0 0 1 */2 * cd /etc/certs && tailscale cert gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx" + "0 0 1 */2 * cd /etc/certs && tailscale cert vm-gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx" ]; }; @@ -114,8 +94,8 @@ in extraConfig = { gitlab = { trustedProxies = [ - "${vpnIp}/32" # The container itself - "100.115.57.8/32" # Public server's IP + "${vpnIp}/32" # The system itself + "100.109.86.8/32" # Public server's IP ]; }; object_store = { @@ -188,22 +168,29 @@ in }; nginx = { + enable = true; clientMaxBodySize = "25000m"; - virtualHosts."gitlab.shire-zebra.ts.net" = { + virtualHosts."vm-gitlab.shire-zebra.ts.net" = { listen = [ { addr = "0.0.0.0"; port = registryPort; ssl = true; } + { + addr = "0.0.0.0"; + port = 443; + ssl = true; + } ]; locations."/" = { - proxyPass = "http://127.0.0.1:4567/"; + proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket"; + #proxyPass = "http://127.0.0.1:4567/"; recommendedProxySettings = true; }; extraConfig = '' - ssl_certificate /etc/certs/gitlab.shire-zebra.ts.net.crt ; - ssl_certificate_key /etc/certs/gitlab.shire-zebra.ts.net.key ; + ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ; + ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ; client_max_body_size 10000m ; ''; }; diff --git a/modules/nix-conf.nix b/modules/nix-conf.nix index 4b4b27c..0d5d7c8 100644 --- a/modules/nix-conf.nix +++ b/modules/nix-conf.nix @@ -41,8 +41,7 @@ in ]; # For home and for work machines substituters = (lib.optionals cfg.cache [ - "http://nas.thehellings.lan:9000/binary-cache/" - "http://nas.home:9000/binary-cache/" + "http://chronicles.shire-zebra.ts.net:9000/binary-cache/" ]) ++ [ "https://ai.cachix.org" @@ -52,8 +51,7 @@ in "https://cache.nixos.org" ]; trusted-public-keys = [ - "nix.thehellings.lan:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8=" - "nix.home:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8=" + "chronicles.shire-zebra.ts.net:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8=" "ai.cachix.org-1:N9dzRK+alWwoKXQlnn0H6aUx0lU/mspIoz8hMvGvbbc=" "nixpkgs-python.cachix.org-1:hxjI7pFxTyuTHn2NkvWCrAUcNZLNS3ZAvfYNuYifcEU=" "greg-hellings.cachix.org-1:y01Jl/L5evlhxdnUW6n56AiI1k8g1wxWhTxJCe7XSco=" From bdd5e08fd97c13f3e9475b3d9d72629bf92b5983 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 12 Jun 2025 04:44:39 +0000 Subject: [PATCH 005/124] Add linode to home --- home/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/home/default.nix b/home/default.nix index 0de9f49..3d51008 100644 --- a/home/default.nix +++ b/home/default.nix @@ -36,5 +36,6 @@ in jude = greg "jude"; isaiah = greg "isaiah"; jeremiah = greg "jeremiah"; + linode = greg "linode"; vm-gitlab = greg "vm-gitlab"; } From 1e28a2250304df26e7454325ed2912d3d9cc683b Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 12 Jun 2025 04:45:03 +0000 Subject: [PATCH 006/124] Update path to src --- home/baseline/ssh.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/home/baseline/ssh.nix b/home/baseline/ssh.nix index d636a70..1fe13c1 100644 --- a/home/baseline/ssh.nix +++ b/home/baseline/ssh.nix @@ -41,7 +41,7 @@ }; "src" = { user = "gitlab"; - hostname = "git.thehellings.lan"; + hostname = "vm-gitlab.shire-zebra.ts.net"; }; srcpub = { user = "gitlab"; From fc813cc4ef8b859e7dfa3714b9ea1acde450c9d1 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 12 Jun 2025 04:48:55 +0000 Subject: [PATCH 007/124] Gitlab now uses https --- hosts/linode/git.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hosts/linode/git.nix b/hosts/linode/git.nix index e92d052..a9ceeaa 100644 --- a/hosts/linode/git.nix +++ b/hosts/linode/git.nix @@ -6,7 +6,7 @@ let in { greg.proxies."${srcDomain}" = { - target = "http://vm-gitlab.shire-zebra.ts.net"; + target = "https://vm-gitlab.shire-zebra.ts.net"; ssl = true; genAliases = false; extraConfig = '' From 676b100e991e703654d7e14a15e892a57cdaeccf Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 11 Jun 2025 23:54:32 -0500 Subject: [PATCH 008/124] Update gitlab-runner configs --- secrets/gitlab/linode-deployer-runner-reg.age | Bin 2165 -> 2175 bytes secrets/gitlab/nixos-qemu-shell.age | Bin 2463 -> 2473 bytes secrets/gitlab/nixos-vbox-shell.age | Bin 2466 -> 2476 bytes 3 files changed, 0 insertions(+), 0 deletions(-) diff --git a/secrets/gitlab/linode-deployer-runner-reg.age b/secrets/gitlab/linode-deployer-runner-reg.age index 13f9e40b8828c5ab2f9083e9d8bb77bf22f686e7..1e1c9394a33722d1fd7f37eaec265502c6652f12 100644 GIT binary patch literal 2175 zcmZY9Im;}06$WsX5t$A|#z4#(OqAxmwREkbLUna5U3*p6+L6^u{cGQst{PNyFcMM0 zKs1m65saKfBjJ7l#XClWG9dQ`ZrNleqc?uvPw+d>b2ujiw})GKY3I66s`6RY0%$~5 z58qgKUHovnqBxGwYXTd>bXqIgJYR5PTdUzI^>R8s+@*6zQxGwDU?R~jfjZD-lT>7@ zC5p^CtR>W<#lbJ|w z$f`ZdyMuHYmsTD2hO$K1&=xcgf|anpR!w7(Volm!y zaU0bsP;-@}1WIXw(yB}@bqdOs>Nz@xG@jF2>f{No2AZxa&qJ<0))+I65U{=o4vH$; zDfSi;h}%B38&14+KH~_MkHd91V120H%dG5Hch#O}JtD>BZY|MrJ)B_gX!pW#qq*m7 z63(WiP^c8NboW@>QBz2o>;8c5mfd3NogFB-5XPi`Gn%w;M1tOsRY#}tgid%z@YTu; z7ILifW;Cm|qcpcwsS;=%f%Ee{Ims~!IZ>5_(=dD4q}K_1jm%kC zs>j)2$m?XVPI~X0!mv&F^H^OW0f~Gu1peY$rg+U|AM#wCy|lL+J*+swQE-(Xt$^(= zXBK2A9k&Vai%#L8ZAXe2%Gk^xUwh}VrsWVmGwV#K%4Dym*8&l3u?x67BxShhfI0Mf zaXQRxeB*hrBN=Apa!Y;U!imxx8I1b=B-8hOwaABRwrH()(m2eggZjQ4#RLB>9Dh;;;6~KYI$|OH}Jz}WS5$h8JS)*HtZZ-xI z3C@*C0&2o>d_N2*P7a`GHqvCw$o$WO*PjENG`i2+Dgwd~7ox!k*QPwt#fLoB3 z;Hz>|=lmiPs*P^Pa&bYHvuyv`|TZ36FP>9;uXj+$3KwV`Q!s<|6d-F>MJm zBq)_uJ3iNlOQg7m(>4~5;DB}PGD`NATG8wcGosq%ht^>*|D;4w(@0i*A~(YsiVTw? z&5_3K%6Rf8v#T*KuQgvG=!Jp2qF@eYNrWX|o;rI=94{1P%?Vw3M!seH3k+6w?tDLO z$Re;h#6qcF-nrRcj0xRVO;w16n)ijQfJ0c;X*d6fNCC;}<1!6zd#r{j~) z#g_3N25VNz30miNmYmc(Ev&01(lMbEMa$Mac}5n<@Dbp6nn|q$#iye|B^e$&WD-VQ zxL9W<){%+$aA>d$YOp{!?MozovN!BjqYksaSa?~^l1{^%GI@2wiCs-ue2+UwZzW{QUd>OP~Mgy%#@y7t>}NpL?6O4TL3yn{!&Q{9u^`%advq-7Yys-DMxuNv`Hv zpdSvi&)QMOE)=t(>1_9t*pTShV@Hcq&;zEgAk|Z1i9MyY%b_-=jm--5dV`6%xQ~dG z(`%MP`zl~6Fo;{Zka9D)i-(CQ*%DAPmQ1^fk0Fsu&5D)!)VYtm-`|LvCK2DiK)u~{*=HPu< z7H&aGsuwW?WC-ShPC%&!XVFQ;$xr1*zuyGmOb{1NolL6oRZJkTlT4{{ zcH;GMvd|l|DJa~rQz^v9g{QPx8Jm{c?0JeYOkU2%X!5!#sXZI3>4?Hr-c$yIvA3jQ ziukR|CSZrgPSToOOjl`3_U@eQbJM?`qULN^6%R7RJ$0jZlTT`!Sy7mbO6{_YsGYSKcch6Gohr1I)hN_*!TD0fV?#+61%&e+ zh60T{&g*WL_5}V}cV=Vb+GeEGm^-t{L}+=2b`ZFZ zMN!3#+<75y)2VbLsE%sf)j0qra4sX%<8Hh!jyNDojKA=N7e>_=g%C9QFS)R}ZGT9t@L`p6wsSP84gF9zap61zd09G1ODLavp8k9;Wj+H0TIk*|K`)o=af*WZ5e-(P&` zZ!drHgYUle&o8`Vzx2EB{`KAed~bN?8=rd9p1%0Yf4uMISDHV)M*S=J{f}O}`ud-L z^#=0#k3S0h;p3mpez5(_dqMei2>;(3@BhvRUi#b*=Qlt9_BUVo^3UIT@5SGLV*CvH Rus8hX`#=5TZ~y)F{{dbd&#nLf diff --git a/secrets/gitlab/nixos-qemu-shell.age b/secrets/gitlab/nixos-qemu-shell.age index ecabf3b43ff53feb4a1f54b5a352970ce898ec22..b1776cd40f1504fc1e67d1ba2eeff8cea006b0bc 100644 GIT binary patch literal 2473 zcmZXV{qN%h9mhRl{9zmZ^55Ycn-TJVu-P#I@ zIm8o9H1dN);!{Mp;{YRvAt)-rCt`TWfkAvC+$CxtUU<*|DtG$*`FnrCEANNT`(t>{ z9w)NWGRbCfbX}Z!z#6LUxuL#V`Fk82#xRJiH__Y(HuY5&>gE!tT9MSB&bSz7`a^{3 z%LPUXdQ;u>?Vx3wUSdtCnk*_rqp`?kSevh*g@jhRHqK?qAFwT0=jmp9+_6G*uEx@K zT3j-rvZ=3OyscM8HbvFtv;w*DfNw=Dv)S))iZNQ}G#_>fvd=~Irsl?T#?U9YaL^tLH!Iz5mxkF^~u>GnXLLAaF$ zV@eOPXqy(w8P1e^EwD$KCpaB>tx#3P^MRt%T@XOzDCmvUNh_ERMacsva)fTDY5m#A z+|p|ei*`Dw)D{UW^GR%E)sUuU#xuAtRdjR9)tphs zTtSeO5Df*uPljEhS>o(Gb|`i`&Cp;=Qj2+)#q&mj zRwDo`IAm(opmyv!dFt82PPas2#h7ozZrJSWWrhZ=g&(wusZvZ8ZOCk=6~iowsk)$) zN);FET&_x4h|6H5cLkug&R`uD2Pzpu(pDgXO9WI+XixbrBkJ11w>F9#MoM5&wrhB) zqzs$fW;2{JX+_)aG~Q05B;SR+daE-<(neDyCvFQW7Nj4xb50#&P6_KWEC9GUTY=za zVk<-~>jzP9t}4UnfR|h`SW1lG29;tlvY+B?1II;p|3KB_@EK7C&e@uE|%8C@*E)_4jp3IkYn6|f<+P;5n~J;CYvr6tpBf5z6@765ZA zacy@LU=BdNrDTq&u{<7fEXPt(X47gCu<2^E(6;B+wFh2XswWIbb?B7R`6^t5DLN+? z`2r4Ifmw%;LM$13EV2`4mUXpSf6l@QyC|jcvWtv!tsMyMxm=3AYSEa0Hzi6RMiBuj ztFxTUgdWh7>OtUYnmJn_cvNNLB$HWaPLC$uBH3z=TrG^Y;5u8rITNtf?`Y&wC!NUv z17>k7l043_7HTmhIkmx#&f^p?=ywPT+kW3tgom<>wn*jNk&1dy6! z6)LpX>@$6MyqdcazbdI(suBttS6beV729FNvJ)abYl#o!bee?id6t?hX6mkN@hm6j zwz#gOI%yzVs~;PimMP7l9y=aR2x0+tQsHI>MGG#3=gX$t6|C*r;wV%Tua3cTm&35FAt{@Y)kX8z52&~p#$&mM z53=bTp6Ma4s`1u7s1p@;5Z9dKMl2TrCRB0*8~7n>g?J)&s%$u5OO{qbZ@!(@j(i&Q z>PoCRtG3LpK#HNd4H9%SvB+{$1JsPzdO#|-EZkMs+!SbSvW|_im01Z5v=hC7!>TrA z+n7s(1h8NYp+SRC>X8zHpS4`5lfYxD9*KnQ@qKs2TRA|XJ&ZB>J`RoI5!MjcLA>eq zYzN5^G?HoewA7Lq-J7Tp2?C(FrESliIy0L9=?FrZ zH9BvHg97NsF*Wbu4WgS!OxaT~hb0G@I`{b6i5G9X_p49Cw=SQ$@b1x94xan|3;UPf zVjsTz@PQ+@a_R*9D-oYFTc2S+ee|=xT|V*SZ+ge<_b8vY z+AS>axqp25>h$<=RDWrow(lD8Q-9dK??tRW*!yz%5qMv6>b&$P#~#^z?1QJxtDGy| zd;XD~M=uIKbn}PJTh8D8O5eZl9`|F?i8qfOe)aLc95qj{PyYSTew}_D|HeyiT!M+W zJ$wJn;1|w4(Yxc!HLvv#zx_h{$@+~y{C5HD648sF@gAE=AFo&H4R6VRWX`$svYj6o zg3n(2iPib(-R_Rdo;!Hb|KjOC{pi5yyS{zu_ouG9;L^u~Ge70+$lc(>ZT|he^LLIK4}S8Z*VBInQFHREpMCd@E66vKosVHR9o(_= zy3d{W`sk+1cYNvMeNP>^^7`)`Idl`@UoHOn7yA$YpevpJx^%}o*I)C?y}x{L*fH9FjBZ`n;`cw{~4iK)SAL*Y$aQSSv&j zA>lYBCg^z>a;R`zjL8`=ppk&5$Ag-K5Fwzb!305q2t@cnB;xny@AnV*%P_biOl%-;*0vAU*K23nnzs<7*{-8-X1GN?Y4u|^5vo)22cX3o{~1^#gG@fLxvD&v``KjZ z&NCau6{GCVn+n~vdDkBh?YR~1rWsnRGwsyH5rM-&+mt5YJk<*UUJ}gG?UCRJ6LMt= zfCGFo6e!m5!&=h7H9%ZJ>Dp&{d8kIzSeKGKmV2<;XIY(R43{72W2WSG(>6jHgq=D< zYmYn9!_F}MMPn1H&QUbSo`BVz;? z#?ls~Wz;0IIFh?QPPlutbtGrewCe(?wL@$KOs%Y}vcZzBOr>GNB9IzMd*+o?yUX

g(KApPqSG0DRSAGds} z)*9x+Fe62yH2}4N+A8UO0K&m0!~tlC!5Fi^mytYS|CKtNsh?0O&>CNOCSxsVk~ zOppj(P8!$AYE#Sx7W2xkb-a9R1g18dun21MVwYU^vpF&=NXl4?889#C zEFo=!Stz@m6g&VaJ9VKcLK|RXs;eeWh#}>Y6+)4qI1}e1v265QuF}_Sfe~9$jRENu zJ`qg00k|X~0eFPZlOz+yi?%bjmWWL2h}+iVo)7P)G4sCNmFhO-Nk%s<45sfI3@Eh$ ztS!Y*9zZ6o;Zh?pfn}VN11%5Oy(onQNHmA~5AydA??8zh@Rrx}yk6hU{G~HT@j@-jZVMDqWS@LRA zEek$si-^Ug_6n_1TB;55;cDthkjc>;)eW?Snc1kskc4j2Qs{)NYrE@|G>vReN>+0* zucSKcXJ%NHEz4>-Y&_*>(awm8?RBD|bYnGYA%G8rBg0rU znLbX^T_+V*i=ej?vhkjF!&cN%I`z_%EpBK>p#oqVkM|H-LXBly>TuOsL8D2JH@y)B zjMSaYLQ--_cMxO9fbpi=#5}JwJNaZYNGgLT;;xkqLkl0J3bC`M+uQXHN3R-ekQWo( ziEx1d+*}8h-lE?!uzU;zgk16fhDlnqu8seE_~Gn{N3Xv4KW{l(&c22B&G#PISDZL> z*6ACtW7Ze<-FnXx_&2^l-G0-v`wyHsap~4izjpM@XMc0meSCQM_c_SB2B>o0%u?IY0k!AE{wU2*k=AN|gU|G4hmb6&dRJwAR^ zz3s+_E{jh;*nRa!N9){q2ieP+r`I2Q@U`>*QdG{ZpZxkgmm1Dh_da-m`~HRCOTbb{i9De1VV_*5!^&ffS+B48E58+qec~V%kpMecu zEiPW4^LO;j&;I+{=g$5?b}yZs`@=QydVJ@@$6nn!@3Bwd&ysh`tGmfhpT6k*KY-?C z*z=FS=Kf+X|MgQZp1gej9~Y-yKJ?}(mw5BNFufiA-z8hmSKAMl&tB9}{`7MA0Px24 z+0T6Z<)gpaH@^-3{IMG^YEq9_y!rSucU?6;aS+)W%^&bz{Q39ZcNY diff --git a/secrets/gitlab/nixos-vbox-shell.age b/secrets/gitlab/nixos-vbox-shell.age index a2bcddf54b651c6eef054b4b0f3fd949583f4f19..96fdfa19d5961c10565e8f0c50fadef522da5968 100644 GIT binary patch literal 2476 zcmZY9{qNia9S874nItzA5Zyp9J3v@w{jR-hdu*HOo zy#|G77$%?#iV&FykwwhL7)E(W49NmPFleUeB!EF60Z~u_OfW8}-=Dwx3toBW^L~GH z*WR#0GhN3^FADcYsSB=Zm5qJX#bUZ)TXhtz5!D8g>9f3=b;snqm;|s_Mh21rddCWx zw3WIw31a{Ya3umy0mBkoq(cjR(HU5&P^ysq-JZeE#i>YT@E-;Bud@g zszqx$Q1Yr5FeA6ap)_GRvfNthq{vMHU053lthkz}FAWM-RbVC#D>Z|kO0WndSrQHF zW1Wjl8V{7vQ;XqB(EXrpnZzhvq$Igj3;MypajPv6c1;XUv%D)BtU(Y4nHv)VlEfg* zA{D3$W+y>aUYwhiSc!}%3Dy$@q=ksq=r!!>>v~S=E~E=fCJRRE)?|nzGPG6GI-X?Y z)maN~%B9nt+GH{&r;0WkG>cqZLNN$qP79u>O9NC_DHS3Wzb_$@Y9dsJ&G^YMEL^40 zwp1i-;{qkcE*;4W7uO9l?{3v}txk@~s=kGG7&9-F!PthUl2_Nc zkmA&-B1M(?C^1qdBY311E4)mkOuLA+w1-6#Poe;`9fY#)Qcz37w`xUi8AfDP2l;Mf zE?kGfI^~E|bHtHUj~F+CQ3kMyjbdG|YerFhmRBseZ;xelvS?21aLs5eSq7ptNA4NNVGrjKk9?H;Hbb4GgTmu+p`rDQvf;aRYFU z49&_gaSUCuuo~?o7(G|qMz8EFTIGQ6YV;5yB*rgIT_pR7xK*R@T*t&JIkFr(&_?Mz z=@1N~Ny5QYvV-BoVek&P55{mmi z=wNUnNKMzF=?q?LN^5KpQm>y2B3@y#R2OEYMmbrx+okNta7O{uVoZLz(wb_9HL(R} zw}g5}+p6{EAi5^2W4|nA1k^;66T7p}uftraXWTS`3owGU7;_*XZ=$mi8&$+QBwE>zaF>2NpxvU|=~zB0D5|u%xdlDOSMabwH|NS4WYO9g zdt3HdkQJ+DM<}v*K`$qvt<4c><(Q~h)H0S{t)Y~iAau{jC}-$yW^-vd zv>HNleKlx1n+J2bj43P`!2<>tIl)dqYtm_~hn0>Qh*{z(cufKabIw2mC>)U~(r8JF zl;bfWw@_gQalUs(ClNcY56LPUPa#3&L)n%2fg3DCloxzv2}&8eG_V=32e{hr72_qe znay$PX~DLXR=4M)j%AIK88B3`2vHab)s={ z_u%+%_*<2;E_mz4gYP%4Jo_8$(dV9g^vOey-oHb*0=W~aD^z;pPc8(wXwDI(RZ#|)Y z_#*Lzn~c-H`qGJ;x#cDAUw7*94|f#T>d!le4~faYj$Z*B1)uxGw%zv6KUcfiIdSsF zYwy|ZUUWj*^ZaAao}((r$7TnvzWSrv{WpHA?(Tg2kBjYx4$}*NsPB3IwO8U7p1HqW|H)PN;qH5HoPMf! zm_7B2KV5p+%a@-2>u4kQPu+3FyKg*maPQgJj`N%JF%5iRbX#Sxx@*r_C+q)sb^qx0 z)td(=vzL}L^@8QTPd)V8A78q2@7=%q%(LKa?(3KAzjv~2*W1OecYg4F^@jZ0###j{^Sx0S#SZ8~^|S literal 2466 zcmZXV{qN%h9mnOAAVba*xC0?)rpSYqyKd{l+K{`W>$UUVSQTH=N6;H zAPPcq7$nFUBOr$;8u1W+AS4J#{!w~T#8 zu!zbqS*?Tp>&ODLW^LcWdK}yPjAaW!ns^~Hl1TBjr#tA$f z6iX9UDH$cAhzK@lXHhF4&KNBhF`$_;idSjFB9w}E6$got&8j1gE7b1CRS(hK?X-1C z`Ep*@Tj)^tL3Y9peH2426=En^wKSts4B?MmF9Ih!hSpCi-e4l}b8M*op&8 z)aBDD$%itzsCDN_CX}6)zK(-*)m5|309>i^z%oms$*o}+rHeQ;n-HXIr_F{dQP1m| zLs$SFDKa*YqXFX2q=*xfDrN&%8V|w(uJB=@dD*bFuE|4wir4{^!r3grT~QW?sUoYG zD=%D6qgcs_#W~sZRHLz-HlMW!m8erTuOXolQY4Faz<#@%%@b-lnQ&ct8mNvgLm6VK zgl}4j~2vs8X?$b)2dhcM2u3iIgPLqSSe1@HlQZx2C<}s-O$1@w@4s7B>7&W z=JYeGnVS$AD6QFA={86Ss?dxu+VEhov6pySsiCHkaTDH7>tOl3E!1I}8MJ47K5f%* zqr1>o*@R4(abx5blAw>;$f!b+c0)BAvsyn4MnJ040|c;DzpWZwdl}6_X-*)+d;@0r zJRCR`NP#xBorWpF6cOrtj`M||O`Two8+PKYr`BrIb%;O+xNfNcShp=$5NwbHU8A}i z90hS~K6T=Ppc_df$9*C7Wzux!fF=@jr=%2q0nn%QtpQGB#;WHndE{EsWB~ihQuhcG zhL)yo$h~lkHL}j8gSjn{E@p+$s8PDma1$45uc{slM*zF#IKuBVQV1xdR_K(Lx9rej zQ(T{>ke2g6aVUK&Z=8X1*FA3fpq9w1>}in;{sVs;Uxip?(s#d3)J6J&NfnHCbY|8pgMaHD7L6 zS^|0wM(2fHDYMK6ovGzb)+*SMBlWbt^};GMg?b8&1rC~yS3EB{&6Q+#?5v_DGk=pC zIt8FBw^cGsoH?>k>m;cNwQQ4#rx{Ahsi_NXwWBOG&2h7;o0eJ%dw4M6@Y9ydUGiBa z)H8Y5Y9ap0=tRt9CKhFZw%dn-t8RM}Sl3K*)4icmPY}0)skBY$K8>z7 z1-B48&2q35#aT3*VcTzmjj*K<^{od5&e&p%VRnx${c>XfEsCRQf1a1N+;>+#fEQUR zbs@NxHzgKcAR(M*x#QIGeDtm>jvV~t;o9dv^6jrZ@Q=4{yzDa%CVMXU^O0vC zdHj~A9{BrrPQ2kM`;Y(ll52PVdgqmB-abY=mtFK1aM!m!cE*MGed6fBJ-g)-H@|XK z?aak@cbZRM_83^o-Hn z%YXjrtP}rw|Nh|q-A7(H=aoOc`SxqY?w5Ph4{!L{)rZ*~vj@NQLXw}4-^3~NC(9=e zUxe&?_TFo6J9*g%6_KKjfD c4=bxnkKcXHzpJzEIdAd9n38{g&7K4Q2Q=YOtpET3 From 09543fbe13c05c28839967700e1abc168880beeb Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 13 Jun 2025 00:17:09 -0500 Subject: [PATCH 009/124] Fix discovering home-manager paths --- pkgs/gen-build/gen-build.go | 32 ++++++++++++++++++++++++++------ 1 file changed, 26 insertions(+), 6 deletions(-) diff --git a/pkgs/gen-build/gen-build.go b/pkgs/gen-build/gen-build.go index e09a818..7db1aeb 100644 --- a/pkgs/gen-build/gen-build.go +++ b/pkgs/gen-build/gen-build.go @@ -41,6 +41,22 @@ func GetNixFlakeOutput() (*NixFlakeOutput, error) { return &flakeOutput, nil } +func GetNixHomeManagerOutput() ([]string, error) { + cmd := exec.Command("nix", "eval", ".#homeConfigurations", "--apply", "hconf: builtins.filter (name: hconf.${name}.pkgs.hostPlatform.isLinux) (builtins.attrNames hconf)", "--json") + output, err := cmd.Output() + if err != nil { + return nil, err + } + + var result []string + err = json.Unmarshal(output, &result) + if err != nil { + return nil, err + } + + return result, nil +} + type GitlabCIJob struct { Stage string `json:"stage"` Tags []string `json:"tags"` @@ -73,12 +89,16 @@ func main() { "nix flake check --no-build", }, } - // Since this is kinda a one-off thing, I can use this directly - // homeConfigurations are treated like they are not known as a - // flake output type. Therefore, it just informs you that it is - // part of the output, but does not evaluate deeper to tell you - // what the name of it is. I will just do this manually for now. - pipeline["Build Home config "] = NewGitlabCIJob("homeConfigurations.\"greg\".activationPackage") + + if flakeOutput.HomeConfigurations != nil { + homeNames, err := GetNixHomeManagerOutput() + if err != nil { + panic(err) + } + for i := range homeNames { + pipeline["Build Home Configuration "+homeNames[i]] = NewGitlabCIJob("homeConfigurations.\"" + homeNames[i] +"\".activationPackage") + } + } if flakeOutput.Apps != nil { for appName := range flakeOutput.Apps { From 61c921cd9102ed3ac567419da5d6107753718404 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 13 Jun 2025 00:37:32 -0500 Subject: [PATCH 010/124] Fix the name of the repo --- .gitlab-ci.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 5c9d14f..0f0c82f 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -49,5 +49,5 @@ default: script: - podman login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" "$CI_REGISTRY" - podman load -i "${IMG}.tar.gz" - - podman tag "localhost/${IMG}:latest" "$CI_REGISTRY/greg/ci-images/${IMG}:latest" - - podman push "$CI_REGISTRY/greg/ci-images/${IMG}:latest" + - podman tag "localhost/${IMG}:latest" "$CI_REGISTRY/greg/nixos-config/${IMG}:latest" + - podman push "$CI_REGISTRY/greg/nixos-config/${IMG}:latest" From aa3953a8b08ad00143ad9904d6a0f359d4f01369 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 13 Jun 2025 02:37:42 -0500 Subject: [PATCH 011/124] Fix pushing to GitLab registry --- hosts/vm-gitlab/default.nix | 64 ++++++++++++++++++++++++------------- 1 file changed, 41 insertions(+), 23 deletions(-) diff --git a/hosts/vm-gitlab/default.nix b/hosts/vm-gitlab/default.nix index c39c78b..e76faa3 100644 --- a/hosts/vm-gitlab/default.nix +++ b/hosts/vm-gitlab/default.nix @@ -169,30 +169,48 @@ in nginx = { enable = true; - clientMaxBodySize = "25000m"; - virtualHosts."vm-gitlab.shire-zebra.ts.net" = { - listen = [ - { - addr = "0.0.0.0"; - port = registryPort; - ssl = true; - } - { - addr = "0.0.0.0"; - port = 443; - ssl = true; - } - ]; - locations."/" = { - proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket"; - #proxyPass = "http://127.0.0.1:4567/"; - recommendedProxySettings = true; + clientMaxBodySize = "10000m"; # 10 GB is fine, right? + virtualHosts = { + "vm-gitlab.shire-zebra.ts.net" = { + listen = [ + { + addr = "0.0.0.0"; + port = 443; + ssl = true; + } + ]; + locations."/" = { + proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket"; + recommendedProxySettings = true; + }; + locations."/v2" = { + proxyPass = "http://127.0.0.1:4567/"; + recommendedProxySettings = true; + }; + extraConfig = '' + ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ; + ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ; + client_max_body_size 10000m ; + ''; + }; + "registry" = { + listen = [ + { + addr = "0.0.0.0"; + port = registryPort; + ssl = true; + } + ]; + locations."/" = { + proxyPass = "http://127.0.0.1:4567/"; + recommendedProxySettings = true; + }; + extraConfig = '' + ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ; + ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ; + client_max_body_size 10000m ; + ''; }; - extraConfig = '' - ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ; - ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ; - client_max_body_size 10000m ; - ''; }; }; From 238ddade0360c50f37318555c305b3745a7aea08 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 17 Jun 2025 15:04:19 -0500 Subject: [PATCH 012/124] Make things stable again Jude is now k3s control plane only Linode connections to vm-gitlab Gitlab settings working properly --- hosts/jude/default.nix | 19 +++++++++++-------- hosts/linode/git.nix | 8 ++++++-- hosts/vm-gitlab/default.nix | 11 +++++------ manifests/databases/ingress.yaml | 2 +- 4 files changed, 23 insertions(+), 17 deletions(-) diff --git a/hosts/jude/default.nix b/hosts/jude/default.nix index 855ad9f..2abbbae 100644 --- a/hosts/jude/default.nix +++ b/hosts/jude/default.nix @@ -160,14 +160,17 @@ # Let's do a sound thing services = { - k3s.extraFlags = - let - ip = (builtins.head config.networking.interfaces.enp14s0u1u2.ipv4.addresses).address; - in - [ - "--tls-san ${ip}" - #"--bind-address ${ip}" - ]; + k3s = { + disableAgent = true; + extraFlags = + let + ip = (builtins.head config.networking.interfaces.enp14s0u1u2.ipv4.addresses).address; + in + [ + "--tls-san ${ip}" + #"--bind-address ${ip}" + ]; + }; pipewire = { enable = true; alsa.enable = true; diff --git a/hosts/linode/git.nix b/hosts/linode/git.nix index a9ceeaa..dec0ef9 100644 --- a/hosts/linode/git.nix +++ b/hosts/linode/git.nix @@ -16,10 +16,14 @@ in ''; }; greg.proxies."registry.thehellings.com" = { - target = "https://vm-gitlab.shire-zebra.ts.net:5000"; + target = "http://vm-gitlab.shire-zebra.ts.net:5000"; ssl = true; genAliases = false; - extraConfig = "client_max_body_size 25000m;"; + extraConfig = '' + proxy_set_header X-Forwarded-Proto https; + proxy_set_header X-Forwarded-Ssl on; + client_max_body_size 25000m; + ''; }; networking.firewall.allowedTCPPorts = [ sshPort ]; diff --git a/hosts/vm-gitlab/default.nix b/hosts/vm-gitlab/default.nix index e76faa3..8679bec 100644 --- a/hosts/vm-gitlab/default.nix +++ b/hosts/vm-gitlab/default.nix @@ -169,7 +169,7 @@ in nginx = { enable = true; - clientMaxBodySize = "10000m"; # 10 GB is fine, right? + clientMaxBodySize = "25000m"; virtualHosts = { "vm-gitlab.shire-zebra.ts.net" = { listen = [ @@ -183,10 +183,6 @@ in proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket"; recommendedProxySettings = true; }; - locations."/v2" = { - proxyPass = "http://127.0.0.1:4567/"; - recommendedProxySettings = true; - }; extraConfig = '' ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ; ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ; @@ -208,8 +204,11 @@ in extraConfig = '' ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ; ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ; - client_max_body_size 10000m ; + client_max_body_size 25000m ; ''; + serverAliases = [ + "vm-gitlab.shire-zebra.ts.net" + ]; }; }; }; diff --git a/manifests/databases/ingress.yaml b/manifests/databases/ingress.yaml index f75c920..21d8ecc 100644 --- a/manifests/databases/ingress.yaml +++ b/manifests/databases/ingress.yaml @@ -14,7 +14,7 @@ spec: - 100.88.91.27 # dns? - 100.80.99.48 # exodus - 100.88.91.27 # genesis - - 100.91.131.66 # gitlab + - 100.117.28.111 # gitlab - 100.68.203.1 # hosea - 100.84.183.79 # isaiah - 100.102.186.39 # jeremiah From 6f3c9c68d5765cb860f6a6b573473f4f0b394302 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 17 Jun 2025 15:26:19 -0500 Subject: [PATCH 013/124] Update zim - both formatting and wikibooks fr hash --- pkgs/zim/blobs.json | 77 ++++++++++++++++++++++++++++++++++++++++++++- 1 file changed, 76 insertions(+), 1 deletion(-) diff --git a/pkgs/zim/blobs.json b/pkgs/zim/blobs.json index 10072fd..2a9f5ba 100644 --- a/pkgs/zim/blobs.json +++ b/pkgs/zim/blobs.json @@ -1 +1,76 @@ -{"en":{"gutenberg":{"name":"gutenberg_en_all_2023-08.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"phet":{"name":"phet_en_all_2023-04.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikibooks":{"name":"wikibooks_en_all_maxi_2021-03.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikipedia":{"name":"wikipedia_en_all_maxi_2024-01.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikisource":{"name":"wikisource_en_all_maxi_2022-09.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikiversity":{"name":"wikiversity_en_all_maxi_2021-03.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wiktionary":{"name":"wiktionary_en_all_nopic_2024-05.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="}},"fr":{"gutenberg":{"name":"gutenberg_fr_all_2023-08.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"phet":{"name":"phet_fr_all_2023-04.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikibooks":{"name":"wikibooks_fr_all_maxi_2024-06.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikipedia":{"name":"wikipedia_fr_all_maxi_2024-05.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikisource":{"name":"wikisource_fr_all_maxi_2022-04.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikiversity":{"name":"wikiversity_fr_all_maxi_2021-02.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wiktionary":{"name":"wiktionary_fr_all_nopic_2024-06.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="}},"ht":{"phet":{"name":"phet_ht_all_2023-04.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikipedia":{"name":"wikipedia_ht_all_maxi_2024-06.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="},"wikisource":{"name":"wikisource_ht_all_maxi_2019-03.zim","hash":"sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo="}}} +{ + "en": { + "gutenberg": { + "name": "gutenberg_en_all_2023-08.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "phet": { + "name": "phet_en_all_2023-04.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wikibooks": { + "name": "wikibooks_en_all_maxi_2021-03.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wikipedia": { + "name": "wikipedia_en_all_maxi_2024-01.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wikisource": { + "name": "wikisource_en_all_maxi_2022-09.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wikiversity": { + "name": "wikiversity_en_all_maxi_2021-03.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wiktionary": { + "name": "wiktionary_en_all_nopic_2024-05.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + } + }, + "fr": { + "gutenberg": { + "name": "gutenberg_fr_all_2023-08.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "phet": { + "name": "phet_fr_all_2023-04.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wikibooks": { + "name": "wikibooks_fr_all_maxi_2024-06.zim", + "hash": "sha256-w/3J2neHPWbz1kK2qR0OB64mkwuDI7RJMuoAWz9yyZs=" + }, + "wikipedia": { + "name": "wikipedia_fr_all_maxi_2024-05.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wikisource": { + "name": "wikisource_fr_all_maxi_2022-04.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wikiversity": { + "name": "wikiversity_fr_all_maxi_2021-02.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wiktionary": { + "name": "wiktionary_fr_all_nopic_2024-06.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + } + }, + "ht": { + "phet": { + "name": "phet_ht_all_2023-04.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wikipedia": { + "name": "wikipedia_ht_all_maxi_2024-06.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + }, + "wikisource": { + "name": "wikisource_ht_all_maxi_2019-03.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + } + } +} From 76e3714bc226c42a332c8c6fe73eabbc0acb7ccd Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 17 Jun 2025 19:54:53 -0500 Subject: [PATCH 014/124] Use HTTPS for registry --- hosts/linode/git.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hosts/linode/git.nix b/hosts/linode/git.nix index dec0ef9..7891a13 100644 --- a/hosts/linode/git.nix +++ b/hosts/linode/git.nix @@ -16,7 +16,7 @@ in ''; }; greg.proxies."registry.thehellings.com" = { - target = "http://vm-gitlab.shire-zebra.ts.net:5000"; + target = "https://vm-gitlab.shire-zebra.ts.net:5000"; ssl = true; genAliases = false; extraConfig = '' From 06ef8be354f82a058e5ea24851ac87da5ac31950 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 17 Jun 2025 19:55:08 -0500 Subject: [PATCH 015/124] Install element on Jude --- home/hosts/jude/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/home/hosts/jude/default.nix b/home/hosts/jude/default.nix index 3b6e8c8..6b68cbd 100644 --- a/home/hosts/jude/default.nix +++ b/home/hosts/jude/default.nix @@ -21,8 +21,8 @@ packages = with pkgs; [ audacity bitwarden-cli + element (mumble.override { pulseSupport = true; }) - #logseq super-productivity webcamoid ]; From cc0eb9df6a67c12566ed88bae48fda39130e5503 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 17 Jun 2025 19:55:27 -0500 Subject: [PATCH 016/124] Update hash for wikiversity_en_all --- pkgs/zim/blobs.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/zim/blobs.json b/pkgs/zim/blobs.json index 2a9f5ba..0ddc9d2 100644 --- a/pkgs/zim/blobs.json +++ b/pkgs/zim/blobs.json @@ -22,7 +22,7 @@ }, "wikiversity": { "name": "wikiversity_en_all_maxi_2021-03.zim", - "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" + "hash": "sha256-w/3J2neHPWbz1kK2qR0OB64mkwuDI7RJMuoAWz9yyZs=" }, "wiktionary": { "name": "wiktionary_en_all_nopic_2024-05.zim", From 81093c16e60afd22fef18fd67557f8d42fa7a66e Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 19 Jun 2025 13:16:42 -0500 Subject: [PATCH 017/124] Add slint plugins --- modules/hm/vscodium.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/modules/hm/vscodium.nix b/modules/hm/vscodium.nix index e0392ce..38e4d0a 100644 --- a/modules/hm/vscodium.nix +++ b/modules/hm/vscodium.nix @@ -38,7 +38,9 @@ in ms-vscode-remote.remote-ssh njpwerner.autodocstring rust-lang.rust-analyzer + slint.slint tamasfe.even-better-toml + vadimcn.vscode-lldb vscjava.vscode-java-test vscjava.vscode-java-dependency vscjava.vscode-java-debug From d7ed0def2e53bf0868df076a30361654d689c9ef Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 19 Jun 2025 22:46:07 -0500 Subject: [PATCH 018/124] Add element and vagrant to jude --- home/hosts/jude/default.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/home/hosts/jude/default.nix b/home/hosts/jude/default.nix index 6b68cbd..e856d14 100644 --- a/home/hosts/jude/default.nix +++ b/home/hosts/jude/default.nix @@ -21,9 +21,10 @@ packages = with pkgs; [ audacity bitwarden-cli - element + element-desktop (mumble.override { pulseSupport = true; }) super-productivity + vagrant webcamoid ]; }; From 1375bb26fc40e6fb8d3477b65e99acb30e784c09 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 19 Jun 2025 23:53:49 -0500 Subject: [PATCH 019/124] Allow doubles on linode --- hosts/linode/nginx.nix | 15 +++++++++++---- hosts/linode/podman.nix | 6 +++++- 2 files changed, 16 insertions(+), 5 deletions(-) diff --git a/hosts/linode/nginx.nix b/hosts/linode/nginx.nix index b64db56..e0a933c 100644 --- a/hosts/linode/nginx.nix +++ b/hosts/linode/nginx.nix @@ -29,9 +29,16 @@ in ports = [ "${homepage}:80" ]; }; }; - greg.proxies."thehellings.com" = { - target = "http://${homepage}/"; - ssl = true; - genAliases = false; + greg.proxies = { + "thehellings.com" = { + target = "http://${homepage}/"; + ssl = true; + genAliases = false; + }; + "doubles.thehellings.com" = { + target = "http://localhost:8081"; + ssl = true; + genAliases = false; + }; }; } diff --git a/hosts/linode/podman.nix b/hosts/linode/podman.nix index 99b3b29..ef0b20f 100644 --- a/hosts/linode/podman.nix +++ b/hosts/linode/podman.nix @@ -1,6 +1,10 @@ -{ ... }: +{ pkgs, ... }: { + environment.systemPackages = with pkgs; [ + podman-compose + ]; + virtualisation.podman = { enable = true; dockerCompat = true; From d8f0d90e6574cefbc4deede9f4cd8cba853dc088 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 19 Jun 2025 23:54:13 -0500 Subject: [PATCH 020/124] Update deps in home manager --- modules/hm/development.nix | 1 + modules/hm/vscodium.nix | 2 +- 2 files changed, 2 insertions(+), 1 deletion(-) diff --git a/modules/hm/development.nix b/modules/hm/development.nix index 2294062..2462847 100644 --- a/modules/hm/development.nix +++ b/modules/hm/development.nix @@ -19,6 +19,7 @@ let nixpkgs-review nodejs process-compose + subversion ]; in with lib; diff --git a/modules/hm/vscodium.nix b/modules/hm/vscodium.nix index 38e4d0a..c909360 100644 --- a/modules/hm/vscodium.nix +++ b/modules/hm/vscodium.nix @@ -40,7 +40,7 @@ in rust-lang.rust-analyzer slint.slint tamasfe.even-better-toml - vadimcn.vscode-lldb + #vadimcn.vscode-lldb vscjava.vscode-java-test vscjava.vscode-java-dependency vscjava.vscode-java-debug From da6f7d5d6ba698e35bed585d935fadacd9b9d13a Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 19 Jun 2025 23:54:37 -0500 Subject: [PATCH 021/124] Sign before pushing to repo --- modules/nixos/remote-builder.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/nixos/remote-builder.nix b/modules/nixos/remote-builder.nix index d32b0f2..e11ffbd 100644 --- a/modules/nixos/remote-builder.nix +++ b/modules/nixos/remote-builder.nix @@ -48,6 +48,7 @@ with lib; set -f export AWS_SHARED_CREDENTIALS_FILE=${config.age.secrets.cache-credentials.path} export IFS=' ' + ${getExe config.nix.package} store sign --recursive --key-file "${config.age.secrets.private-cache.path}" "$@" ${getExe config.nix.package} copy --to "s3://binary-cache/?scheme=http&endpoint=nas.home%3A9000&profile=default" "$@" '' ); From 27f1e34d49c0a833f8e39d74dbd5a28caaf19c3e Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sun, 22 Jun 2025 00:26:25 -0500 Subject: [PATCH 022/124] Update VSCode plugins --- modules/hm/vscodium.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/hm/vscodium.nix b/modules/hm/vscodium.nix index c909360..4e3f3de 100644 --- a/modules/hm/vscodium.nix +++ b/modules/hm/vscodium.nix @@ -34,13 +34,13 @@ in jnoortheen.nix-ide mkhl.direnv ms-python.python + ms-vscode.cpptools-extension-pack ms-vscode.makefile-tools ms-vscode-remote.remote-ssh njpwerner.autodocstring rust-lang.rust-analyzer slint.slint tamasfe.even-better-toml - #vadimcn.vscode-lldb vscjava.vscode-java-test vscjava.vscode-java-dependency vscjava.vscode-java-debug From e62c88b9769fb808aa71cd032a52e3fc15ceff9a Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sun, 22 Jun 2025 00:26:31 -0500 Subject: [PATCH 023/124] Update pins --- flake.lock | 84 +++++++++++++++++++++++++++--------------------------- 1 file changed, 42 insertions(+), 42 deletions(-) diff --git a/flake.lock b/flake.lock index 4ff927e..9b76edc 100644 --- a/flake.lock +++ b/flake.lock @@ -10,11 +10,11 @@ "systems": "systems" }, "locked": { - "lastModified": 1747575206, - "narHash": "sha256-NwmAFuDUO/PFcgaGGr4j3ozG9Pe5hZ/ogitWhY+D81k=", + "lastModified": 1750173260, + "narHash": "sha256-9P1FziAwl5+3edkfFcr5HeGtQUtrSdk/MksX39GieoA=", "owner": "ryantm", "repo": "agenix", - "rev": "4835b1dc898959d8547a871ef484930675cb47f1", + "rev": "531beac616433bac6f9e2a19feb8e99a22a66baf", "type": "github" }, "original": { @@ -74,11 +74,11 @@ ] }, "locked": { - "lastModified": 1749194393, - "narHash": "sha256-vt6hM9DNywnXXuW1qPDLzECmbDcmxhh58wpb0EEQjAo=", + "lastModified": 1750325256, + "narHash": "sha256-vvlxGz/waqJ3TGqM/iqXbnEc7/R1qnEXmaBiPaQ1RE0=", "owner": "lnl7", "repo": "nix-darwin", - "rev": "19346808c445f23b08652971be198b9df6c33edc", + "rev": "0d71cbf88d63e938b37b85b3bf8b238bcf7b39b9", "type": "github" }, "original": { @@ -226,11 +226,11 @@ "nixpkgs-lib": "nixpkgs-lib_2" }, "locked": { - "lastModified": 1748821116, - "narHash": "sha256-F82+gS044J1APL0n4hH50GYdPRv/5JWm34oCJYmVKdE=", + "lastModified": 1749398372, + "narHash": "sha256-tYBdgS56eXYaWVW3fsnPQ/nFlgWi/Z2Ymhyu21zVM98=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "49f0870db23e8c1ca0b5259734a02cd9e1e371a1", + "rev": "9305fe4e5c2a6fcf5ba6a3ff155720fbe4076569", "type": "github" }, "original": { @@ -321,11 +321,11 @@ ] }, "locked": { - "lastModified": 1749657191, - "narHash": "sha256-QLilaHuhGxiwhgceDWESj9gFcKIdEp7+9lRqNGpN8S4=", + "lastModified": 1750304462, + "narHash": "sha256-Mj5t4yX05/rXnRqJkpoLZTWqgStB88Mr/fegTRqyiWc=", "owner": "nix-community", "repo": "home-manager", - "rev": "faeab32528a9360e9577ff4082de2d35c6bbe1ce", + "rev": "863842639722dd12ae9e37ca83bcb61a63b36f6c", "type": "github" }, "original": { @@ -406,11 +406,11 @@ }, "nix-hardware": { "locked": { - "lastModified": 1749195551, - "narHash": "sha256-W5GKQHgunda/OP9sbKENBZhMBDNu2QahoIPwnsF6CeM=", + "lastModified": 1750431636, + "narHash": "sha256-vnzzBDbCGvInmfn2ijC4HsIY/3W1CWbwS/YQoFgdgPg=", "owner": "nixos", "repo": "nixos-hardware", - "rev": "4602f7e1d3f197b3cb540d5accf5669121629628", + "rev": "1552a9f4513f3f0ceedcf90320e48d3d47165712", "type": "github" }, "original": { @@ -565,11 +565,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1749285348, - "narHash": "sha256-frdhQvPbmDYaScPFiCnfdh3B/Vh81Uuoo0w5TkWmmjU=", + "lastModified": 1750365781, + "narHash": "sha256-XE/lFNhz5lsriMm/yjXkvSZz5DfvKJLUjsS6pP8EC50=", "owner": "nixos", "repo": "nixpkgs", - "rev": "3e3afe5174c561dee0df6f2c2b2236990146329f", + "rev": "08f22084e6085d19bcfb4be30d1ca76ecb96fe54", "type": "github" }, "original": { @@ -597,11 +597,11 @@ }, "nixunstable": { "locked": { - "lastModified": 1749285348, - "narHash": "sha256-frdhQvPbmDYaScPFiCnfdh3B/Vh81Uuoo0w5TkWmmjU=", + "lastModified": 1750365781, + "narHash": "sha256-XE/lFNhz5lsriMm/yjXkvSZz5DfvKJLUjsS6pP8EC50=", "owner": "nixos", "repo": "nixpkgs", - "rev": "3e3afe5174c561dee0df6f2c2b2236990146329f", + "rev": "08f22084e6085d19bcfb4be30d1ca76ecb96fe54", "type": "github" }, "original": { @@ -621,11 +621,11 @@ "systems": "systems_4" }, "locked": { - "lastModified": 1749644591, - "narHash": "sha256-v72hZJvAA78+LWohTzTwk/OnzsNxbkoTM+G7+iXwdl0=", + "lastModified": 1750345447, + "narHash": "sha256-yOuSSfI4xovXQpSkZUK02CBcY1f0Nvm0RhnUN8xn2rY=", "owner": "nix-community", "repo": "nixvim", - "rev": "64f0d3c86a7894cad9b09bb1015375ffb9949d70", + "rev": "6a1a348ab1f00bd32d2392b5c2fc72489c699af3", "type": "github" }, "original": { @@ -642,11 +642,11 @@ "treefmt-nix": "treefmt-nix" }, "locked": { - "lastModified": 1749670360, - "narHash": "sha256-YmJ5Zffr6tJID0nA3XkQaoeDLFhOZKBtvZl31jXsqQg=", + "lastModified": 1750538863, + "narHash": "sha256-zabhNRMe/a16+QvrwtTqsfs915O3EYfxqOyHJyUSpRs=", "owner": "nix-community", "repo": "NUR", - "rev": "74f88e0178318b15c3c6d8832c681cc4e72c3d92", + "rev": "6bd3d204ea7b9ceba96011d2bcbfa2e07e2c93d5", "type": "github" }, "original": { @@ -665,11 +665,11 @@ ] }, "locked": { - "lastModified": 1749531675, - "narHash": "sha256-UB8Mc88rW9frjpJ1Fj2ro7f07Gg8dX3uVXvMXnFR4CE=", + "lastModified": 1749730855, + "narHash": "sha256-L3x2nSlFkXkM6tQPLJP3oCBMIsRifhIDPMQQdHO5xWo=", "owner": "NuschtOS", "repo": "search", - "rev": "4029d450d0266909ee52775849b7da54e79b328e", + "rev": "8dfe5879dd009ff4742b668d9c699bc4b9761742", "type": "github" }, "original": { @@ -680,11 +680,11 @@ }, "patched-nixpkgs": { "locked": { - "lastModified": 1748133736, - "narHash": "sha256-8DCZF+SHXa7P9O9op2ET7qJtPomzQ49jy2vjzrHocg4=", + "lastModified": 1750323031, + "narHash": "sha256-UBervAoXyQgWMLqN684fD5FMW4NsYdy5rqlJwMC1hd4=", "owner": "TomaSajt", "repo": "nixpkgs", - "rev": "76121e3e5db9bfcc4b604b4093abea7b1aa3109e", + "rev": "76ef3a6c51ed221a7ac29b50c94bb48589979be5", "type": "github" }, "original": { @@ -702,11 +702,11 @@ "utils": "utils" }, "locked": { - "lastModified": 1749385025, - "narHash": "sha256-2w6+xAMdT9LgMxDHaIyddMTacBbF7RjaZFyGjjTDBhg=", + "lastModified": 1750064469, + "narHash": "sha256-yaEzei8/2LBZL+h0iKO28eeP1Cvl5v0piAyakZfZL0s=", "owner": "SaumonNet", "repo": "proxmox-nixos", - "rev": "48f39fbe2e8f90f9ac160dd4b6929f3ac06d8223", + "rev": "8df841766fab6c15341577b6982ddd368be72113", "type": "github" }, "original": { @@ -869,11 +869,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1749607503, - "narHash": "sha256-ou8BXMfitXrT5dAuxcx3g2kIg3akNe8TdPmxaPlf5UU=", + "lastModified": 1750471394, + "narHash": "sha256-IdOUn2DcabUAa42nthbyIY+frX42tTkU9KGddbpq5H4=", "owner": "nix-community", "repo": "nix-vscode-extensions", - "rev": "06a79e7e0edfcbe28b3e60c78d91c9f75998a8f3", + "rev": "8368fd526c329cb83a00f9e3cbc35a89599d5ced", "type": "github" }, "original": { @@ -912,11 +912,11 @@ "patched-nixpkgs": "patched-nixpkgs" }, "locked": { - "lastModified": 1749228292, - "narHash": "sha256-cavxEaS1a1jQqkQsGVUiu3Hlex3wqUfFB1LE2TXT0vA=", + "lastModified": 1750341075, + "narHash": "sha256-/7jUMPTFaGLNAQETRhDCM8L7cjI1Q39ismxLcEG+sK0=", "owner": "HPsaucii", "repo": "zed-editor-flake", - "rev": "db6c84831c7bedcf63dcecf1e0b59cddea302c62", + "rev": "dbcdd13e513562d7cf4a0b2459fea16129f688e4", "type": "github" }, "original": { From a6d2067ff7484e92d00f0ffc6b69d7a27bf5abb8 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 23 Jun 2025 09:19:16 -0500 Subject: [PATCH 024/124] Improvements to IVR --- home/default.nix | 1 + home/hosts/ivr/default.nix | 1 + modules/hm/gui/bookmarks.nix | 17 +++++++++++++++++ 3 files changed, 19 insertions(+) diff --git a/home/default.nix b/home/default.nix index 3d51008..c5dab44 100644 --- a/home/default.nix +++ b/home/default.nix @@ -32,6 +32,7 @@ let in { "MacBook-Pro.local" = user "aarch64-darwin" "ivr" "gregory.hellings"; + "jude.thehellings.lan" = user "aarch64-darwin" "ivr" "gregory.hellings"; # This is annoying, but DNS is a pain for the shared docking station exodus = greg "exodus"; jude = greg "jude"; isaiah = greg "isaiah"; diff --git a/home/hosts/ivr/default.nix b/home/hosts/ivr/default.nix index cb6e825..0456b80 100644 --- a/home/hosts/ivr/default.nix +++ b/home/hosts/ivr/default.nix @@ -37,6 +37,7 @@ in kubectl minikube mise + nil nixStable pipenv-ivr pre-commit diff --git a/modules/hm/gui/bookmarks.nix b/modules/hm/gui/bookmarks.nix index 81e16fc..ace7be0 100644 --- a/modules/hm/gui/bookmarks.nix +++ b/modules/hm/gui/bookmarks.nix @@ -63,6 +63,19 @@ } ]; } + { + name = "IC"; + bookmarks = [ + { + name = "Azure Portal/Console"; + url = "https://portal.azure.com"; + } + { + name = "Azure Code"; + url = "https://dev.azure.com"; + } + ]; + } { name = "Processes"; bookmarks = [ @@ -78,6 +91,10 @@ name = "DB Request"; url = "https://ivrtg.aha.io/develop/features/INFR-1073"; } + { + name = "Deploy"; + url = "https://ivrtg.aha.io/develop/features/EN-1000"; + } { name = "Server list"; url = "https://ivrtg.atlassian.net/wiki/spaces/ITS/pages/13009166/350+Main"; From 87e615135ceb5510598194be88ca916e71dc6dc3 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 24 Jun 2025 01:39:59 -0500 Subject: [PATCH 025/124] Update pins and make Zed configuration --- flake.lock | 60 +++++++++++++++++++++++----------------------- modules/hm/zed.nix | 59 +++++++++++++++++++++++++++++++++++++++++---- 2 files changed, 85 insertions(+), 34 deletions(-) diff --git a/flake.lock b/flake.lock index 9b76edc..ce7323a 100644 --- a/flake.lock +++ b/flake.lock @@ -74,11 +74,11 @@ ] }, "locked": { - "lastModified": 1750325256, - "narHash": "sha256-vvlxGz/waqJ3TGqM/iqXbnEc7/R1qnEXmaBiPaQ1RE0=", + "lastModified": 1750618568, + "narHash": "sha256-w9EG5FOXrjXGfbqCcQg9x1lMnTwzNDW5BMXp8ddy15E=", "owner": "lnl7", "repo": "nix-darwin", - "rev": "0d71cbf88d63e938b37b85b3bf8b238bcf7b39b9", + "rev": "1dd19f19e4b53a1fd2e8e738a08dd5fe635ec7e5", "type": "github" }, "original": { @@ -321,11 +321,11 @@ ] }, "locked": { - "lastModified": 1750304462, - "narHash": "sha256-Mj5t4yX05/rXnRqJkpoLZTWqgStB88Mr/fegTRqyiWc=", + "lastModified": 1750730235, + "narHash": "sha256-rZErlxiV7ssvI8t7sPrKU+fRigNc2KvoKZG3gtUtK50=", "owner": "nix-community", "repo": "home-manager", - "rev": "863842639722dd12ae9e37ca83bcb61a63b36f6c", + "rev": "d07e9cceb4994ed64a22b9b36f8b76923e87ac38", "type": "github" }, "original": { @@ -363,11 +363,11 @@ "nixpkgs": "nixpkgs_2" }, "locked": { - "lastModified": 1749636823, - "narHash": "sha256-WUaIlOlPLyPgz9be7fqWJA5iG6rHcGRtLERSCfUDne4=", + "lastModified": 1750684550, + "narHash": "sha256-uLtw0iF9mQ94L831NOlQLPX9wm0qzd5yim3rcwACEoM=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "623c56286de5a3193aa38891a6991b28f9bab056", + "rev": "fae816c55a75675f30d18c9cbdecc13b970d95d4", "type": "github" }, "original": { @@ -565,11 +565,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1750365781, - "narHash": "sha256-XE/lFNhz5lsriMm/yjXkvSZz5DfvKJLUjsS6pP8EC50=", + "lastModified": 1750506804, + "narHash": "sha256-VLFNc4egNjovYVxDGyBYTrvVCgDYgENp5bVi9fPTDYc=", "owner": "nixos", "repo": "nixpkgs", - "rev": "08f22084e6085d19bcfb4be30d1ca76ecb96fe54", + "rev": "4206c4cb56751df534751b058295ea61357bbbaa", "type": "github" }, "original": { @@ -597,11 +597,11 @@ }, "nixunstable": { "locked": { - "lastModified": 1750365781, - "narHash": "sha256-XE/lFNhz5lsriMm/yjXkvSZz5DfvKJLUjsS6pP8EC50=", + "lastModified": 1750506804, + "narHash": "sha256-VLFNc4egNjovYVxDGyBYTrvVCgDYgENp5bVi9fPTDYc=", "owner": "nixos", "repo": "nixpkgs", - "rev": "08f22084e6085d19bcfb4be30d1ca76ecb96fe54", + "rev": "4206c4cb56751df534751b058295ea61357bbbaa", "type": "github" }, "original": { @@ -621,11 +621,11 @@ "systems": "systems_4" }, "locked": { - "lastModified": 1750345447, - "narHash": "sha256-yOuSSfI4xovXQpSkZUK02CBcY1f0Nvm0RhnUN8xn2rY=", + "lastModified": 1750691276, + "narHash": "sha256-F507hXG4ORVpvuFeuoyDo/bmO/rR2PJRB7XhtDuBnBE=", "owner": "nix-community", "repo": "nixvim", - "rev": "6a1a348ab1f00bd32d2392b5c2fc72489c699af3", + "rev": "1f3e5741a927b5b0a983f08ab9d3bcf313bc141e", "type": "github" }, "original": { @@ -642,11 +642,11 @@ "treefmt-nix": "treefmt-nix" }, "locked": { - "lastModified": 1750538863, - "narHash": "sha256-zabhNRMe/a16+QvrwtTqsfs915O3EYfxqOyHJyUSpRs=", + "lastModified": 1750731829, + "narHash": "sha256-1UT2YgiY9MD0kuWkdnjR4UAKCeaIEME5dd8xMrvuSg8=", "owner": "nix-community", "repo": "NUR", - "rev": "6bd3d204ea7b9ceba96011d2bcbfa2e07e2c93d5", + "rev": "cad648060595395298331aa99efe2f4acecfd6a0", "type": "github" }, "original": { @@ -680,11 +680,11 @@ }, "patched-nixpkgs": { "locked": { - "lastModified": 1750323031, - "narHash": "sha256-UBervAoXyQgWMLqN684fD5FMW4NsYdy5rqlJwMC1hd4=", + "lastModified": 1750677113, + "narHash": "sha256-hOLEPjPscArQiPm4+EPuVuvcXX7uhIx18gLvXrDS/5k=", "owner": "TomaSajt", "repo": "nixpkgs", - "rev": "76ef3a6c51ed221a7ac29b50c94bb48589979be5", + "rev": "27a4b311a7ea290aa2504019c8693b7dace8dab5", "type": "github" }, "original": { @@ -869,11 +869,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1750471394, - "narHash": "sha256-IdOUn2DcabUAa42nthbyIY+frX42tTkU9KGddbpq5H4=", + "lastModified": 1750730765, + "narHash": "sha256-MIcOcvxqAXUv2TJjf19aVXdtVrD8Gkcfi4W4pKkT0Lw=", "owner": "nix-community", "repo": "nix-vscode-extensions", - "rev": "8368fd526c329cb83a00f9e3cbc35a89599d5ced", + "rev": "1a1442e13dc1730de0443f80dcf02658365e999a", "type": "github" }, "original": { @@ -912,11 +912,11 @@ "patched-nixpkgs": "patched-nixpkgs" }, "locked": { - "lastModified": 1750341075, - "narHash": "sha256-/7jUMPTFaGLNAQETRhDCM8L7cjI1Q39ismxLcEG+sK0=", + "lastModified": 1750686425, + "narHash": "sha256-8GK4ofgwZFfHxMv/2nDcnIbkDd+3O5qI96kgGx8iczA=", "owner": "HPsaucii", "repo": "zed-editor-flake", - "rev": "dbcdd13e513562d7cf4a0b2459fea16129f688e4", + "rev": "4e8e32b58f3095116dd9404f0ea030173626eb15", "type": "github" }, "original": { diff --git a/modules/hm/zed.nix b/modules/hm/zed.nix index 442bca2..718ab42 100644 --- a/modules/hm/zed.nix +++ b/modules/hm/zed.nix @@ -12,9 +12,60 @@ in options.greg.zed = lib.mkEnableOption "Whether to install the Zed editor"; config = lib.mkIf cfg { - home.packages = with pkgs; [ - nil - zed-editor - ]; + programs.zed-editor = { + enable = true; + extensions = [ + "ansible" + "cargo-tom" + "dockerfile" + "mcp-server-gitlab" + "helm" + "html" + "ini" + "jsonnet" + "latex" + "make" + "markdown-oxide" + "material-icon-theme" + "nix" + "nu" + "postgres-context-server" + "python-refactoring" + "slint" + "snippets" + "toml" + ]; + extraPackages = with pkgs; [ + cargo + direnv + nil + nix + python3 + rustc + ]; + installRemoteServer = true; + userKeymaps = [ + { + } + ]; + userSettings = { + baseKeymap = "VSCode"; + buffer_font_size = 16; + features = { + copilot = true; + }; + relative_line_numbers = true; + telemetry = { + metrics = true; + }; + theme = { + mode = "system"; + light = "Gruvbox Dark"; + dark = "One Dark"; + }; + vim_mode = true; + ui_font_size = 20; + }; + }; }; } From b65a615d21a238c4b0c550bfb802821a433361f5 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 24 Jun 2025 08:21:32 -0500 Subject: [PATCH 026/124] Add Audacity and DBeaver to IVR box --- darwin/default.nix | 1 + darwin/hosts/ivr/default.nix | 2 ++ 2 files changed, 3 insertions(+) diff --git a/darwin/default.nix b/darwin/default.nix index 5b5451b..b6340f0 100644 --- a/darwin/default.nix +++ b/darwin/default.nix @@ -36,4 +36,5 @@ let in rec { "MacBook-Pro" = mac { name = "ivr"; }; + "MacBook-Prolocal" = mac { name = "ivr"; }; } diff --git a/darwin/hosts/ivr/default.nix b/darwin/hosts/ivr/default.nix index 73a12a8..fcffb1d 100644 --- a/darwin/hosts/ivr/default.nix +++ b/darwin/hosts/ivr/default.nix @@ -23,9 +23,11 @@ in ]; casks = [ "alt-tab" + "audacity" "bitwarden" "bruno" "chromium" + "dbeaver-community" "firefox" "microsoft-teams" "onlyoffice" From 86a371b0aab552a105175d3c21f28dd1d0a93e18 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 24 Jun 2025 13:28:52 -0500 Subject: [PATCH 027/124] Update starship config --- home/hosts/ivr/default.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/home/hosts/ivr/default.nix b/home/hosts/ivr/default.nix index 0456b80..5bb0000 100644 --- a/home/hosts/ivr/default.nix +++ b/home/hosts/ivr/default.nix @@ -69,6 +69,14 @@ in starship = { enable = true; enableNushellIntegration = true; + settings = { + directory = { + home_symbol = "~"; + truncate_to_repo = false; + truncation_length = 0; + use_os_path_sep = true; + }; + }; }; tmux.shell = (lib.getExe x); }; From 853562128e648b394d47d566b19025a3b67c1500 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 24 Jun 2025 22:44:32 -0500 Subject: [PATCH 028/124] Update zims --- pkgs/zim.nix | 22 +++++++++++++++++----- pkgs/zim/blobs.json | 20 ++++++++++---------- pkgs/zim/updater.go | 25 +++++++++++++------------ 3 files changed, 40 insertions(+), 27 deletions(-) diff --git a/pkgs/zim.nix b/pkgs/zim.nix index fa5ca1b..873089a 100644 --- a/pkgs/zim.nix +++ b/pkgs/zim.nix @@ -2,7 +2,7 @@ callPackage, fetchtorrent, lib, - stdenv, + stdenvNoCC, ... }: let @@ -10,9 +10,21 @@ let # Converts the inputs from the file into a fetchtorrent command zim = type: val: - (fetchtorrent { - inherit (val) hash name; - url = "https://download.kiwix.org/zim/${type}/${val.name}.torrent"; + stdenvNoCC.mkDerivation (finalAttrs: { + inherit (val) name; + src = ( + fetchtorrent { + inherit (val) hash; + url = "https://download.kiwix.org/zim/${type}/${val.name}.torrent"; + backend = "rqbit"; + postUnpack = "ls -lR"; + } + ); + phases = [ "installPhase" ]; + installPhase = '' + ls -lR ${finalAttrs.src} + cp ${finalAttrs.src} $out + ''; }); rawZims = builtins.fromJSON (builtins.readFile ./zim/blobs.json); # Uses the function above to convert the JSON into a structure of fetchtorrent derivations @@ -26,7 +38,7 @@ let ) ); in -stdenv.mkDerivation { +stdenvNoCC.mkDerivation { name = "zims"; version = "2024-10"; diff --git a/pkgs/zim/blobs.json b/pkgs/zim/blobs.json index 0ddc9d2..7558223 100644 --- a/pkgs/zim/blobs.json +++ b/pkgs/zim/blobs.json @@ -5,7 +5,7 @@ "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "phet": { - "name": "phet_en_all_2023-04.zim", + "name": "phet_en_all_2025-03.zim", "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wikibooks": { @@ -21,8 +21,8 @@ "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wikiversity": { - "name": "wikiversity_en_all_maxi_2021-03.zim", - "hash": "sha256-w/3J2neHPWbz1kK2qR0OB64mkwuDI7RJMuoAWz9yyZs=" + "name": "wikiversity_en_all_maxi_2025-05.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wiktionary": { "name": "wiktionary_en_all_nopic_2024-05.zim", @@ -35,19 +35,19 @@ "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "phet": { - "name": "phet_fr_all_2023-04.zim", + "name": "phet_fr_all_2025-03.zim", "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wikibooks": { - "name": "wikibooks_fr_all_maxi_2024-06.zim", - "hash": "sha256-w/3J2neHPWbz1kK2qR0OB64mkwuDI7RJMuoAWz9yyZs=" + "name": "wikibooks_fr_all_maxi_2025-06.zim", + "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wikipedia": { "name": "wikipedia_fr_all_maxi_2024-05.zim", "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wikisource": { - "name": "wikisource_fr_all_maxi_2022-04.zim", + "name": "wikisource_fr_all_maxi_2025-06.zim", "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wikiversity": { @@ -55,17 +55,17 @@ "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wiktionary": { - "name": "wiktionary_fr_all_nopic_2024-06.zim", + "name": "wiktionary_fr_all_nopic_2025-03.zim", "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" } }, "ht": { "phet": { - "name": "phet_ht_all_2023-04.zim", + "name": "phet_ht_all_2025-03.zim", "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wikipedia": { - "name": "wikipedia_ht_all_maxi_2024-06.zim", + "name": "wikipedia_ht_all_maxi_2025-05.zim", "hash": "sha256-pQpattmS9VmO3ZIQUFn66az8GSmB4IvYhTTCFn6SUmo=" }, "wikisource": { diff --git a/pkgs/zim/updater.go b/pkgs/zim/updater.go index 3a71293..0cebf8c 100644 --- a/pkgs/zim/updater.go +++ b/pkgs/zim/updater.go @@ -81,19 +81,20 @@ func getHash(ch chan result, file, category, language string) { // in the existing file fmt.Printf("Fetching hash for %s\n", file) cmd := exec.Command("nix-prefetch", - "--option", - "extra-experimental-features", - "flakes", - fmt.Sprintf(`fetchtorrent { + "--option", + "extra-experimental-features", + "flakes", + fmt.Sprintf(`fetchtorrent { url="%s/%s/%s.torrent"; hash="sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA="; + backend="rqbit"; }`, BASE, category, file), - ) - out, err := cmd.Output() - if err != nil { - panic(err) - } - ch <- result{ category, language, strings.TrimSpace(string(out)) } + ) + out, err := cmd.Output() + if err != nil { + panic(err) + } + ch <- result{category, language, strings.TrimSpace(string(out))} } func outputIsValid(o map[string]map[string]Zim) bool { @@ -128,7 +129,7 @@ func main() { if _, ok := output[lang]; !ok { output[lang] = make(map[string]Zim) } - output[lang][t] = Zim{ file, "" } + output[lang][t] = Zim{file, ""} go getHash(comms, file, t, lang) } } @@ -144,6 +145,6 @@ func main() { break } } - ret, _ := json.Marshal(output) + ret, _ := json.MarshalIndent(output, " ", "") fmt.Println(string(ret)) } From aae3867944fd5c884f9e895656a83f4d26461091 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 24 Jun 2025 22:44:52 -0500 Subject: [PATCH 029/124] Update zed settings --- modules/hm/zed.nix | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/modules/hm/zed.nix b/modules/hm/zed.nix index 718ab42..bebe8a5 100644 --- a/modules/hm/zed.nix +++ b/modules/hm/zed.nix @@ -46,11 +46,32 @@ in installRemoteServer = true; userKeymaps = [ { + context = "Editor && (showing_completions || showing code actions)"; + bindings = { + enter = "editor::Newline"; + escape = "editor:Cancel"; + }; } ]; userSettings = { + agent = { + default_model = { + provider = "copilot_chat"; + model = "claude-4"; + }; + single_file_review = true; + version = "2"; + }; baseKeymap = "VSCode"; buffer_font_size = 16; + edit_predictions = { + copilot = { + proxy = null; + proxy_no_verify = null; + }; + enable_in_text_threads = false; + mode = "subtle"; + }; features = { copilot = true; }; @@ -63,6 +84,9 @@ in light = "Gruvbox Dark"; dark = "One Dark"; }; + vim = { + toggle_relative_line_numbers = true; + }; vim_mode = true; ui_font_size = 20; }; From 4516958b91cfebe6a092558febf01fe13e192ee8 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 1 Jul 2025 22:33:18 -0400 Subject: [PATCH 030/124] Add some TUI tools Add rainfrog for databases Add tenere for LLMs Add jqp for playing with jq scripts Add wiki-tui for wikipedia Add iamb for Matrix --- flake.lock | 48 +++++++++++++++++++------------------- home/baseline/default.nix | 1 + home/baseline/tools.nix | 10 ++++++++ home/default.nix | 1 + home/hosts/ivr/default.nix | 2 ++ 5 files changed, 38 insertions(+), 24 deletions(-) create mode 100644 home/baseline/tools.nix diff --git a/flake.lock b/flake.lock index ce7323a..c910ced 100644 --- a/flake.lock +++ b/flake.lock @@ -321,11 +321,11 @@ ] }, "locked": { - "lastModified": 1750730235, - "narHash": "sha256-rZErlxiV7ssvI8t7sPrKU+fRigNc2KvoKZG3gtUtK50=", + "lastModified": 1750798083, + "narHash": "sha256-DTCCcp6WCFaYXWKFRA6fiI2zlvOLCf5Vwx8+/0R8Wc4=", "owner": "nix-community", "repo": "home-manager", - "rev": "d07e9cceb4994ed64a22b9b36f8b76923e87ac38", + "rev": "ff31a4677c1a8ae506aa7e003a3dba08cb203f82", "type": "github" }, "original": { @@ -363,11 +363,11 @@ "nixpkgs": "nixpkgs_2" }, "locked": { - "lastModified": 1750684550, - "narHash": "sha256-uLtw0iF9mQ94L831NOlQLPX9wm0qzd5yim3rcwACEoM=", + "lastModified": 1750779888, + "narHash": "sha256-wibppH3g/E2lxU43ZQHC5yA/7kIKLGxVEnsnVK1BtRg=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "fae816c55a75675f30d18c9cbdecc13b970d95d4", + "rev": "16ec914f6fb6f599ce988427d9d94efddf25fe6d", "type": "github" }, "original": { @@ -406,11 +406,11 @@ }, "nix-hardware": { "locked": { - "lastModified": 1750431636, - "narHash": "sha256-vnzzBDbCGvInmfn2ijC4HsIY/3W1CWbwS/YQoFgdgPg=", + "lastModified": 1750837715, + "narHash": "sha256-2m1ceZjbmgrJCZ2PuQZaK4in3gcg3o6rZ7WK6dr5vAA=", "owner": "nixos", "repo": "nixos-hardware", - "rev": "1552a9f4513f3f0ceedcf90320e48d3d47165712", + "rev": "98236410ea0fe204d0447149537a924fb71a6d4f", "type": "github" }, "original": { @@ -565,11 +565,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1750506804, - "narHash": "sha256-VLFNc4egNjovYVxDGyBYTrvVCgDYgENp5bVi9fPTDYc=", + "lastModified": 1750741721, + "narHash": "sha256-Z0djmTa1YmnGMfE9jEe05oO4zggjDmxOGKwt844bUhE=", "owner": "nixos", "repo": "nixpkgs", - "rev": "4206c4cb56751df534751b058295ea61357bbbaa", + "rev": "4b1164c3215f018c4442463a27689d973cffd750", "type": "github" }, "original": { @@ -597,11 +597,11 @@ }, "nixunstable": { "locked": { - "lastModified": 1750506804, - "narHash": "sha256-VLFNc4egNjovYVxDGyBYTrvVCgDYgENp5bVi9fPTDYc=", + "lastModified": 1750741721, + "narHash": "sha256-Z0djmTa1YmnGMfE9jEe05oO4zggjDmxOGKwt844bUhE=", "owner": "nixos", "repo": "nixpkgs", - "rev": "4206c4cb56751df534751b058295ea61357bbbaa", + "rev": "4b1164c3215f018c4442463a27689d973cffd750", "type": "github" }, "original": { @@ -621,11 +621,11 @@ "systems": "systems_4" }, "locked": { - "lastModified": 1750691276, - "narHash": "sha256-F507hXG4ORVpvuFeuoyDo/bmO/rR2PJRB7XhtDuBnBE=", + "lastModified": 1750879244, + "narHash": "sha256-ClV6rZbPnd5wIcBYNiCdrbhtSzY6dwPRA4Z/z1cFcyo=", "owner": "nix-community", "repo": "nixvim", - "rev": "1f3e5741a927b5b0a983f08ab9d3bcf313bc141e", + "rev": "f0764db7212003520341ac10ddcee50e9c458a6f", "type": "github" }, "original": { @@ -642,11 +642,11 @@ "treefmt-nix": "treefmt-nix" }, "locked": { - "lastModified": 1750731829, - "narHash": "sha256-1UT2YgiY9MD0kuWkdnjR4UAKCeaIEME5dd8xMrvuSg8=", + "lastModified": 1750879289, + "narHash": "sha256-2kq9yVW4rMuidAqn0YWWt9B/5WsuzXPyoH46bQGN8rU=", "owner": "nix-community", "repo": "NUR", - "rev": "cad648060595395298331aa99efe2f4acecfd6a0", + "rev": "82688d18898c7f521cdaa8c4b6d182f34a2a1acd", "type": "github" }, "original": { @@ -869,11 +869,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1750730765, - "narHash": "sha256-MIcOcvxqAXUv2TJjf19aVXdtVrD8Gkcfi4W4pKkT0Lw=", + "lastModified": 1750817194, + "narHash": "sha256-9CCF4ANxZUXHwz74SeGQkFi4OYnm0BD2I3GeQvxMKPM=", "owner": "nix-community", "repo": "nix-vscode-extensions", - "rev": "1a1442e13dc1730de0443f80dcf02658365e999a", + "rev": "fc01ad517af163c76d4493c5959fc5c44244a97f", "type": "github" }, "original": { diff --git a/home/baseline/default.nix b/home/baseline/default.nix index eb9891d..9c3876c 100644 --- a/home/baseline/default.nix +++ b/home/baseline/default.nix @@ -8,6 +8,7 @@ ./git.nix ./nushell.nix ./ssh.nix + ./tools.nix ./vim ./xonsh.nix ]; diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix new file mode 100644 index 0000000..e4e7543 --- /dev/null +++ b/home/baseline/tools.nix @@ -0,0 +1,10 @@ +{ pkgs, ... }: +{ + home.packages = with pkgs; [ + jqp + iamb + rainfrog + tenere + wiki-tui + ]; +} diff --git a/home/default.nix b/home/default.nix index c5dab44..c7e7eb8 100644 --- a/home/default.nix +++ b/home/default.nix @@ -32,6 +32,7 @@ let in { "MacBook-Pro.local" = user "aarch64-darwin" "ivr" "gregory.hellings"; + "MacBook-Prolocal.local" = user "aarch64-darwin" "ivr" "gregory.hellings"; "jude.thehellings.lan" = user "aarch64-darwin" "ivr" "gregory.hellings"; # This is annoying, but DNS is a pain for the shared docking station exodus = greg "exodus"; jude = greg "jude"; diff --git a/home/hosts/ivr/default.nix b/home/hosts/ivr/default.nix index 5bb0000..0e0354e 100644 --- a/home/hosts/ivr/default.nix +++ b/home/hosts/ivr/default.nix @@ -41,6 +41,8 @@ in nixStable pipenv-ivr pre-commit + python311 + python3Packages.flake8 skaffold x ]; From f1f38d85ece67b9d0aabe9bdfe58c1e206273582 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 1 Jul 2025 23:24:14 -0500 Subject: [PATCH 031/124] More updates to jude for new role --- home/hosts/jude/default.nix | 20 +++++++------- hosts/jude/default.nix | 52 ++++++++++--------------------------- 2 files changed, 23 insertions(+), 49 deletions(-) diff --git a/home/hosts/jude/default.nix b/home/hosts/jude/default.nix index e856d14..479287f 100644 --- a/home/hosts/jude/default.nix +++ b/home/hosts/jude/default.nix @@ -2,11 +2,11 @@ { greg = { - development = true; - gui = true; + development = false; + gui = false; gnome = false; - vscodium = true; - zed = true; + vscodium = false; + zed = false; }; home = { @@ -19,13 +19,13 @@ ''; packages = with pkgs; [ - audacity + #audacity bitwarden-cli - element-desktop - (mumble.override { pulseSupport = true; }) - super-productivity - vagrant - webcamoid + #element-desktop + #(mumble.override { pulseSupport = true; }) + #super-productivity + #vagrant + #webcamoid ]; }; diff --git a/hosts/jude/default.nix b/hosts/jude/default.nix index 2abbbae..7462e58 100644 --- a/hosts/jude/default.nix +++ b/hosts/jude/default.nix @@ -19,7 +19,7 @@ greg = { tailscale.enable = true; - gnome.enable = true; + gnome.enable = false; kde.enable = false; kubernetes.enable = true; podman.enable = true; @@ -72,34 +72,15 @@ ]; hardware = { - nvidia = - let - gpl_symbols_linux_615_patch = pkgs.fetchpatch { - url = "https://github.com/CachyOS/kernel-patches/raw/914aea4298e3744beddad09f3d2773d71839b182/6.15/misc/nvidia/0003-Workaround-nv_vm_flags_-calling-GPL-only-code.patch"; - hash = "sha256-YOTAvONchPPSVDP9eJ9236pAPtxYK5nAePNtm2dlvb4="; - stripLen = 1; - extraPrefix = "kernel/"; - }; - in - { - #package = config.boot.kernelPackages.nvidiaPackages.vulkan_beta; - package = config.boot.kernelPackages.nvidiaPackages.mkDriver { - version = "575.57.08"; - openSha256 = "sha256-DOJw73sjhQoy+5R0GHGnUddE6xaXb/z/Ihq3BKBf+lg="; - sha256_64bit = "sha256-KqcB2sGAp7IKbleMzNkB3tjUTlfWBYDwj50o3R//xvI="; - settingsSha256 = "sha256-AIeeDXFEo9VEKCgXnY3QvrW5iWZeIVg4LBCeRtMs5Io="; - persistencedSha256 = "sha256-Len7Va4HYp5r3wMpAhL4VsPu5S0JOshPFywbO7vYnGo="; - usePersistenced = true; - patches = [ gpl_symbols_linux_615_patch ]; - }; - modesetting.enable = true; - powerManagement = { - enable = false; - finegrained = false; - }; - nvidiaSettings = true; - open = true; + nvidia = { + modesetting.enable = true; + powerManagement = { + enable = false; + finegrained = false; }; + nvidiaSettings = true; + open = true; + }; system76 = { firmware-daemon.enable = true; #kernel-modules.enable = true; @@ -114,23 +95,16 @@ interfaces = { # This seems to be direct mother board interface enp12s0.useDHCP = true; - #enp12s0.ipv4.addresses = [ - #{ - #address = "10.42.1.11"; - #prefixLength = 16; - #} - #]; - # This seems to be the one that comes through the monitor hookup - enp14s0u1u2.ipv4.addresses = [ + enp12s0.ipv4.addresses = [ { - address = "10.42.1.10"; + address = "10.42.1.11"; prefixLength = 16; } ]; }; defaultGateway = { address = "10.42.1.1"; - interface = "enp14s0u1u2"; + interface = "enp12s0"; }; nameservers = [ "10.42.1.5" @@ -164,7 +138,7 @@ disableAgent = true; extraFlags = let - ip = (builtins.head config.networking.interfaces.enp14s0u1u2.ipv4.addresses).address; + ip = (builtins.head config.networking.interfaces.enp12s0.ipv4.addresses).address; in [ "--tls-san ${ip}" From f9f1357b8eb7f7d90ebc42950dc151be93e1a68f Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 2 Jul 2025 11:55:35 -0500 Subject: [PATCH 032/124] Rename of Jude to Zeke Since Jude is a now a server, we rename it to Zeke, for Ezekiel Update of tailscale to auto-register nodes Update kubernetes to install the etcd application Update Zeke IP address and DNS bindings --- home/default.nix | 2 +- home/hosts/{jude => zeke}/default.nix | 0 hosts/baseline.nix | 10 +- hosts/default.nix | 2 +- hosts/genesis/net/hosts | 7 +- hosts/genesis/networking/dhcp.nix | 2 +- hosts/jude/default.nix | 166 ------------------ hosts/jude/work.nix | 14 -- hosts/{jude => zeke}/boot.nix | 0 hosts/zeke/default.nix | 84 +++++++++ .../{jude => zeke}/hardware-configuration.nix | 0 hosts/{jude => zeke}/virt.nix | 8 - manifests/databases/ingress.yaml | 2 +- modules/nixos/kubernetes.nix | 1 + modules/nixos/tailscale.nix | 10 +- secrets/secrets.nix | 1 + secrets/tailscale.age | 40 +++++ 17 files changed, 147 insertions(+), 202 deletions(-) rename home/hosts/{jude => zeke}/default.nix (100%) delete mode 100644 hosts/jude/default.nix delete mode 100644 hosts/jude/work.nix rename hosts/{jude => zeke}/boot.nix (100%) create mode 100644 hosts/zeke/default.nix rename hosts/{jude => zeke}/hardware-configuration.nix (100%) rename hosts/{jude => zeke}/virt.nix (94%) create mode 100644 secrets/tailscale.age diff --git a/home/default.nix b/home/default.nix index c7e7eb8..29caf42 100644 --- a/home/default.nix +++ b/home/default.nix @@ -35,7 +35,7 @@ in "MacBook-Prolocal.local" = user "aarch64-darwin" "ivr" "gregory.hellings"; "jude.thehellings.lan" = user "aarch64-darwin" "ivr" "gregory.hellings"; # This is annoying, but DNS is a pain for the shared docking station exodus = greg "exodus"; - jude = greg "jude"; + zeke = greg "zeke"; isaiah = greg "isaiah"; jeremiah = greg "jeremiah"; linode = greg "linode"; diff --git a/home/hosts/jude/default.nix b/home/hosts/zeke/default.nix similarity index 100% rename from home/hosts/jude/default.nix rename to home/hosts/zeke/default.nix diff --git a/hosts/baseline.nix b/hosts/baseline.nix index 510e9a0..fc580f7 100644 --- a/hosts/baseline.nix +++ b/hosts/baseline.nix @@ -4,7 +4,6 @@ overlays, pkgs, self, - top, ... }: let @@ -148,11 +147,11 @@ in ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOjQjXq9WYU2Ki27BR9WwJ4ZruS/lJXbjC1b0Q42Adi0"; }; - jude = { + zeke = { extraHostNames = [ - "jude.home" - "jude.thehellings.lan" - "jude-builder" + "zeke.home" + "zeke.thehellings.lan" + "zeke-builder" ]; publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOos0zQePsa+T6Z2dsKbPOvEdrBQ8a6mx3s7pN6ysCI0"; }; @@ -170,6 +169,7 @@ in # Enable the OpenSSH daemon for remote control services = { + locate.enable = true; openssh = { enable = true; settings.X11Forwarding = true; diff --git a/hosts/default.nix b/hosts/default.nix index 9975175..1e132df 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -44,7 +44,7 @@ in { genesis = unstable { name = "genesis"; }; exodus = unstable { name = "exodus"; }; - jude = unstable { name = "jude"; }; + zeke = unstable { name = "zeke"; }; icdm-root = unstable { name = "icdm-root"; }; linode = unstable { name = "linode"; }; hosea = unstable { name = "hosea"; }; diff --git a/hosts/genesis/net/hosts b/hosts/genesis/net/hosts index cc877ec..53dafd0 100644 --- a/hosts/genesis/net/hosts +++ b/hosts/genesis/net/hosts @@ -13,9 +13,10 @@ 10.42.1.7 hosea hosea.thehellings.lan 10.42.1.8 jeremiah jeremiah.thehellings.lan minio-02.thehellings.lan 10.42.1.9 ivr ivr.thehellings.lan -10.42.1.10 jude jude.thehellings.lan -10.42.1.11 jude1 jude1.thehellings.lan +# 10 - monitor +# 11 - old jude 10.42.1.12 tv +10.42.1.13 zeke zeke.thehellings.lan # VMs 10.42.4.1 matrix matrix.thehellings.lan @@ -34,7 +35,7 @@ 100.68.203.1 hosea.home hosea.shire-zebra.ts.net 100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes postgres.kubernetes 100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes -100.90.74.19 jude.home +100.90.74.19 zeke.home 100.115.57.8 linode.home 100.65.5.38 matrix.home matrix.shire-zebra.ts.net 100.127.55.22 jellyfin.home diff --git a/hosts/genesis/networking/dhcp.nix b/hosts/genesis/networking/dhcp.nix index 63bb46f..8572be3 100644 --- a/hosts/genesis/networking/dhcp.nix +++ b/hosts/genesis/networking/dhcp.nix @@ -107,7 +107,7 @@ } { hw-address = "04:7c:16:d5:60:6f"; - ip-address = "10.42.1.11"; # Jude - but straight in the motherboard + ip-address = "10.42.1.13"; # Zeke - but straight in the motherboard } ######################################## diff --git a/hosts/jude/default.nix b/hosts/jude/default.nix deleted file mode 100644 index 7462e58..0000000 --- a/hosts/jude/default.nix +++ /dev/null @@ -1,166 +0,0 @@ -{ - config, - lib, - pkgs, - top, - ... -}: - -{ - imports = [ - ./boot.nix - ./hardware-configuration.nix - ./virt.nix - ./work.nix - top.nix-hardware.nixosModules.system76 - ]; - - boot.extraModulePackages = [ config.boot.kernelPackages.v4l2loopback ]; - - greg = { - tailscale.enable = true; - gnome.enable = false; - kde.enable = false; - kubernetes.enable = true; - podman.enable = true; - print.enable = true; - remote-builder.enable = true; - }; - - environment.systemPackages = - with pkgs; - lib.mkMerge [ - [ - # for Immersed - cudatoolkit - immersed - libva - ] - [ - bind # For things like nslookup - create_ssl - distrobox - expect - fswatch - gimp - go - gparted - graphviz - flock - ffmpeg - handbrake - imagemagick - libtheora - libxml2 - linode-cli - makemkv - oathToolkit - usbutils - ventoy - ] - - [ - # Video/Audio data composition framework tools like "gst-inspect", "gst-launch" ... - gst_all_1.gstreamer - gst_all_1.gst-plugins-base - gst_all_1.gst-plugins-good - gst_all_1.gst-plugins-bad - gst_all_1.gst-plugins-ugly - gst_all_1.gst-libav - gst_all_1.gst-vaapi - ] - ]; - - hardware = { - nvidia = { - modesetting.enable = true; - powerManagement = { - enable = false; - finegrained = false; - }; - nvidiaSettings = true; - open = true; - }; - system76 = { - firmware-daemon.enable = true; - #kernel-modules.enable = true; - }; - }; - - networking = { - hostName = "jude"; - networkmanager.enable = lib.mkForce true; - enableIPv6 = false; - useDHCP = false; - interfaces = { - # This seems to be direct mother board interface - enp12s0.useDHCP = true; - enp12s0.ipv4.addresses = [ - { - address = "10.42.1.11"; - prefixLength = 16; - } - ]; - }; - defaultGateway = { - address = "10.42.1.1"; - interface = "enp12s0"; - }; - nameservers = [ - "10.42.1.5" - "10.42.1.1" - ]; - firewall = { - enable = false; - allowedTCPPorts = [ 21000 ]; - allowedUDPPorts = [ - 21000 - 21010 - ]; - }; - }; - - programs = { - adb.enable = true; - steam.enable = true; - nix-index = { - enable = true; - enableBashIntegration = false; - enableFishIntegration = false; - enableZshIntegration = false; - }; - nix-ld.enable = false; - }; - - # Let's do a sound thing - services = { - k3s = { - disableAgent = true; - extraFlags = - let - ip = (builtins.head config.networking.interfaces.enp12s0.ipv4.addresses).address; - in - [ - "--tls-san ${ip}" - #"--bind-address ${ip}" - ]; - }; - pipewire = { - enable = true; - alsa.enable = true; - audio.enable = true; - jack.enable = true; - pulse.enable = true; - wireplumber.enable = true; - }; - pulseaudio.enable = false; # This conflicts with pipewire - locate.enable = true; - xserver.videoDrivers = [ "nvidia" ]; - }; - - users.users.greg.extraGroups = [ - "adbusers" - "kvm" - "podman" - ]; -} diff --git a/hosts/jude/work.nix b/hosts/jude/work.nix deleted file mode 100644 index a51b511..0000000 --- a/hosts/jude/work.nix +++ /dev/null @@ -1,14 +0,0 @@ -{ pkgs, ... }: - -{ - services.mongodb = { - enable = false; - }; - environment.systemPackages = with pkgs; [ - mongodb-compass - pipenv-ivr - pre-commit - python311 - stdenv.cc - ]; -} diff --git a/hosts/jude/boot.nix b/hosts/zeke/boot.nix similarity index 100% rename from hosts/jude/boot.nix rename to hosts/zeke/boot.nix diff --git a/hosts/zeke/default.nix b/hosts/zeke/default.nix new file mode 100644 index 0000000..c1df80a --- /dev/null +++ b/hosts/zeke/default.nix @@ -0,0 +1,84 @@ +{ + config, + lib, + top, + ... +}: + +{ + imports = [ + ./boot.nix + ./hardware-configuration.nix + ./virt.nix + top.nix-hardware.nixosModules.system76 + ]; + + boot.extraModulePackages = [ config.boot.kernelPackages.v4l2loopback ]; + + greg = { + tailscale.enable = true; + kubernetes.enable = true; + remote-builder.enable = true; + }; + + hardware = { + nvidia = { + modesetting.enable = true; + powerManagement = { + enable = false; + finegrained = false; + }; + nvidiaSettings = true; + open = true; + }; + system76 = { + firmware-daemon.enable = true; + #kernel-modules.enable = true; + }; + }; + + networking = { + hostName = "zeke"; + networkmanager.enable = lib.mkForce true; + enableIPv6 = false; + useDHCP = false; + interfaces = { + # This seems to be direct mother board interface + enp12s0.useDHCP = true; + enp12s0.ipv4.addresses = [ + { + address = "10.42.1.13"; + prefixLength = 16; + } + ]; + }; + defaultGateway = { + address = "10.42.1.1"; + interface = "enp12s0"; + }; + nameservers = [ + "10.42.1.5" + "10.42.1.1" + ]; + }; + + # Let's do a sound thing + services = { + k3s = { + extraFlags = + let + ip = (builtins.head config.networking.interfaces.enp12s0.ipv4.addresses).address; + in + [ + "--tls-san ${ip}" + #"--bind-address ${ip}" + ]; + }; + xserver.videoDrivers = [ "nvidia" ]; + }; + + users.users.greg.extraGroups = [ + "kvm" + "podman" + ]; +} diff --git a/hosts/jude/hardware-configuration.nix b/hosts/zeke/hardware-configuration.nix similarity index 100% rename from hosts/jude/hardware-configuration.nix rename to hosts/zeke/hardware-configuration.nix diff --git a/hosts/jude/virt.nix b/hosts/zeke/virt.nix similarity index 94% rename from hosts/jude/virt.nix rename to hosts/zeke/virt.nix index c04871d..b1943be 100644 --- a/hosts/jude/virt.nix +++ b/hosts/zeke/virt.nix @@ -20,12 +20,6 @@ in { specialisation = { vbox.configuration = { - - greg = { - podman.enable = lib.mkForce false; - vmdev.enable = lib.mkForce false; - }; - users.extraGroups.vboxusers.members = [ "greg" ]; virtualisation = { @@ -81,8 +75,6 @@ in ]; }; - greg.vmdev.enable = true; - hardware.graphics.enable = true; services.gitlab-runner = { diff --git a/manifests/databases/ingress.yaml b/manifests/databases/ingress.yaml index 21d8ecc..c42fb46 100644 --- a/manifests/databases/ingress.yaml +++ b/manifests/databases/ingress.yaml @@ -18,7 +18,7 @@ spec: - 100.68.203.1 # hosea - 100.84.183.79 # isaiah - 100.102.186.39 # jeremiah - - 100.90.74.19 # jude + - 100.90.74.19 # zeke - 100.115.57.8 # linode - 100.65.5.38 # matrix - 100.127.55.22 # jellyfin diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index a30cf49..d3aed94 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -27,6 +27,7 @@ in }; environment.systemPackages = [ + pkgs.etcd pkgs.fluxcd pkgs.kubectl-cnpg pkgs.kubernetes-helm diff --git a/modules/nixos/tailscale.nix b/modules/nixos/tailscale.nix index 810930c..ff7fe78 100644 --- a/modules/nixos/tailscale.nix +++ b/modules/nixos/tailscale.nix @@ -9,13 +9,19 @@ in }; config = lib.mkIf cfg.enable { - services.tailscale.enable = true; - networking.firewall.checkReversePath = "loose"; + age.secrets.tailscale-key.file = ../../secrets/tailscale.age; boot.kernel.sysctl = { "net.ipv4.ip_forward" = "1"; "net.ipv6.conf.all.forwarding" = "1"; }; environment.systemPackages = [ config.services.tailscale.package ]; + networking.firewall.checkReversePath = "loose"; + services.tailscale = { + enable = true; + authKeyFile = config.age.secrets.tailscale-key.path; + authKeyParameters.preauthorized = true; + useRoutingFeatures = "both"; + }; systemd.services.tailscaled.partOf = [ "network-online.target" ]; }; } diff --git a/secrets/secrets.nix b/secrets/secrets.nix index 0282f14..2fa244c 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -48,6 +48,7 @@ in { # Demo of how to create it "matrix.age".publicKeys = everyone; + "tailscale.age".publicKeys = everyone; # At the point where you want to use it, put # age.secrets.matrix.file = ../../secrets/matrix.age; # Then you can reference the file at /run/agenix/matrix diff --git a/secrets/tailscale.age b/secrets/tailscale.age new file mode 100644 index 0000000..77154c9 --- /dev/null +++ b/secrets/tailscale.age @@ -0,0 +1,40 @@ +age-encryption.org/v1 +-> ssh-ed25519 64uajw eoKKdFba2XcbCVKnIOtdC2ONeyi/dE1twqMaSqXKkEc +prfPB9NCpJo8tzzuhWznhxvMldAi0YTPUhW6AWiQvE4 +-> ssh-ed25519 oyEmTw DLXlNmyaCz7tmSfQPl/SwTQ+wOdNNYbFTm1Y76PpBzg +YJBWt1zdMO47Om7gs38SCeMa7dw+t5/73TgDSYaUdZI +-> ssh-ed25519 mOmPfg bTVKIB7INbEG+PXSL8YcP74fy7ECQKt/MPmTDpCiQQo +AfZYePt24h0ELGArl//fJiR/7slWdrc/Ezxu0LqxQUk +-> ssh-ed25519 YJiRbw WsRrdW0GeYO3VJyZWpQ29LTRfTt0nPdVBgmMc6YAwgU +I4npJcHxKOMVYjbfw69sZCCPIucjFiEt0h5vjSDw7RM +-> ssh-ed25519 aY2AXA whCyGvPQiNn1PSYLXx37fFWDwYDcK+r0MPQJYQcAIDg +/b9ANzkjXLRuubCtUZW6egQaUkugRmzd29tVet2hT9w +-> ssh-ed25519 xNtnoA 180eVN3lr/cMHjz4PGMMk1+G/y8Dot2sWn4bSIdYTS4 +K0RjcWsvMS28wlvA1MAluika8zbdxgunYI7JCQ07M70 +-> ssh-ed25519 AQhf1g ctCXtqVmBCPhEGFOzqh1C3XSqEaE9f28yNSJvWp/ZTo +bD+cbqv2TOugtvSyk6wxqA0GtlOvIQuUNKtizfzhvOA +-> ssh-ed25519 B8wa7Q UTJugYfOOIbaJnekia96nyfMRRbGbgmbJnAOdtQXkXw ++qMZomWoP83M8df0ENMxhLOI+SbYAsXnpEgsqc58RWg +-> ssh-ed25519 8UnW5Q xQNVaJMaPWSpZa1YmTBrq8IYU8bt8tqNWjbDdmmLnlk +s9SsfK5M6VaAYUe+xsDn2Hb3bBrG5jsj/nnQC2q5KyU +-> ssh-ed25519 0/WsKg Q62P2TPgR7ZGrh3IQ44GR36BE138xXvitpqjUka9DB0 +X6cXT+KX3b+6eocOUMj7HnYIL6McDaEAkHcJtNG0zXA +-> ssh-ed25519 Nl/5yA QzloGeZn8MJJJXoYZWIyfROOInYc8DMtChwNFdo2oHQ +ZRpi/vsdZ9AhBQ3y4Ef80EVQASh+LV5oaQ6ORRZJq0A +-> ssh-ed25519 GdLgCQ /YUxOpKyfXyRVKpvbVo2WFUPI1ybsV6r4Qc5lePTuyI +AlpzElB1nmreZgxXra7m9Bmg01CmEE4cCa55iQsOus8 +-> ssh-ed25519 tOH/HQ D8XB9uWUjvxuuY1Cw91OgM0HTBjHR53jdXzTz6vSPW4 +CNDdFdCx/DpDinLfmkzC2+eqhmMeeFKlb4E8uL5+7p8 +-> ssh-ed25519 FpzvfQ Q+BhCWFka6CjuBQkq52YL6h5zgAIxOFBi0XotIsSg1A +QTjopNycjnDN+7QWBkpanaxvyAlJSuoiZXX4qt/Wap4 +-> ssh-ed25519 kdPvzQ hEuPZpdsql8cgOIzh275mcCllJ4LiRXcgytuh422CD4 +P/yZGDmUxCUI2Mw8n3mvtLTe3AQS35PwEtd7t8opNOI +-> ssh-ed25519 onmXpg aHON6nzJV7CaoFcaiwRjKIGZ0Iuwt0sg9/6xm88K1HU +egBgoaXi/yG/p7ZgbxcMblj1whEeXY1nc854G2CPEfU +-> ssh-ed25519 CnhD0g 14R8ZAmBI40N78Y7E9yPzzAxN3pV3aprrW3/ww/pYTo +y3ntuDWMEKfaIWQSJGAkP9bfH4RiRRPLzkeHtJknPSg +-> ssh-ed25519 4ep2UA RByTE9k8SWeuY1lC/cnfukePKjkOWN2PErHox+br/B4 +n5v3/oGmyoxcqMG95zdSuBKJ+LQHO1ODAOmXyYkrd4U +--- IWNk1uhB1uTeMC1V9zajj5S3WQ223Jp/VjUUI98mDZk +ۊ9:YQ);O#,N<, Date: Wed, 2 Jul 2025 12:00:25 -0500 Subject: [PATCH 033/124] Use impala instead of gomuks --- home/baseline/tools.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index e4e7543..cbb18ce 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -3,6 +3,7 @@ home.packages = with pkgs; [ jqp iamb + impala rainfrog tenere wiki-tui From 6c4cc2cd30d3b015cbb5595a7e6f18c07e973b96 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 2 Jul 2025 12:01:10 -0500 Subject: [PATCH 034/124] Rewrite deploy --- home/baseline/xonsh.nix | 1 - home/baseline/xonsh_footer.xsh | 8 ++++++++ 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/home/baseline/xonsh.nix b/home/baseline/xonsh.nix index 86960f1..5893947 100644 --- a/home/baseline/xonsh.nix +++ b/home/baseline/xonsh.nix @@ -56,7 +56,6 @@ s = "nix run \".#runserver\""; # Nix related ones - deploy = "nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host"; gl-nging = "sudo nixos-container run gitlab -- systemctl restart nginx"; nb = "nix build -L"; nixdu = "sudo nix-store --gc --print-roots | egrep -v r\"^(/nix/var|/run/\\w+-system|\\{memory|/proc)\""; diff --git a/home/baseline/xonsh_footer.xsh b/home/baseline/xonsh_footer.xsh index e5246dc..b8ed214 100644 --- a/home/baseline/xonsh_footer.xsh +++ b/home/baseline/xonsh_footer.xsh @@ -63,6 +63,14 @@ def _rebuild(args): popd aliases['rebuild'] = _rebuild +def _deploy(args): + dest = args[0] + if dest != "linode": + nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host @(dest) --build-host @(dest) + else: + nixos-rebuild swtich --use-remote-sudo --use-substitutes --target-host @(dest) +aliases['deploy'] = _deploy + def _yaml2json(args, stdin=None, stdout=None): import sys, yaml, json from yaml import CLoader From 9940e89d2ecdbb11a006e95bc075c77387ad05fc Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 2 Jul 2025 23:07:08 -0500 Subject: [PATCH 035/124] Add keepalived to cluster Add keepalived for the Kubernetes cluster Set VIP to 10.42.5.1 Set *.cluster DNS resolution to this IP address But do not move existing *.kubernetes targets, yet, as there is a need to ensure that subnet routers are properly configured --- hosts/genesis/net/hosts | 3 ++ hosts/isaiah/default.nix | 6 ++- hosts/jeremiah/default.nix | 6 ++- hosts/zeke/default.nix | 6 ++- modules/nixos/kubernetes.nix | 71 ++++++++++++++++++++++++++++-------- 5 files changed, 74 insertions(+), 18 deletions(-) diff --git a/hosts/genesis/net/hosts b/hosts/genesis/net/hosts index 53dafd0..5228fd0 100644 --- a/hosts/genesis/net/hosts +++ b/hosts/genesis/net/hosts @@ -23,6 +23,9 @@ 10.42.4.2 jellyfin jellyfin.thehellings.lan vm-jellyfin vm-jellyfin.thehellings.lan 10.42.4.3 git gitlab git.thehellings.lan gitlab.thehellings.lan +# VIP +10.42.5.1 pgadmin.cluter postgres.cluster matrix.cluster + # IPMI 10.42.100.6 isaiahbmc isaiahbmc.thehellings.lan diff --git a/hosts/isaiah/default.nix b/hosts/isaiah/default.nix index 31cc0dc..9b9825d 100644 --- a/hosts/isaiah/default.nix +++ b/hosts/isaiah/default.nix @@ -35,7 +35,11 @@ }; greg = { - kubernetes.enable = true; + kubernetes = { + enable = true; + vipInterface = "enp38s0"; + priority = 255; + }; tailscale.enable = true; remote-builder.enable = true; }; diff --git a/hosts/jeremiah/default.nix b/hosts/jeremiah/default.nix index 5b26fd2..d4dcfeb 100644 --- a/hosts/jeremiah/default.nix +++ b/hosts/jeremiah/default.nix @@ -75,7 +75,11 @@ in greg = { home = true; - kubernetes.enable = true; + kubernetes = { + enable = true; + vipInterface = "br0"; + priority = 254; + }; tailscale.enable = true; remote-builder.enable = true; }; diff --git a/hosts/zeke/default.nix b/hosts/zeke/default.nix index c1df80a..e0cddf6 100644 --- a/hosts/zeke/default.nix +++ b/hosts/zeke/default.nix @@ -17,7 +17,11 @@ greg = { tailscale.enable = true; - kubernetes.enable = true; + kubernetes = { + enable = true; + vipInterface = "enp12s0"; + priority = 253; + }; remote-builder.enable = true; }; diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index d3aed94..cd0b647 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -16,6 +16,16 @@ in default = false; description = "Whether to run the Kubernetes agent only"; }; + priority = lib.mkOption { + type = lib.types.int; + default = 1; + description = "VIP priority"; + }; + vipInterface = lib.mkOption { + type = lib.types.str; + default = null; + description = "Interface to attach VIP for clustering onto"; + }; }; }; @@ -55,21 +65,52 @@ in allowedUDPPorts = [ 8472 ]; }; - services.k3s = { - enable = true; - role = if cfg.agentOnly then "agent" else "server"; - tokenFile = config.age.secrets.kubernetesToken.path; - extraFlags = [ - "--cluster-cidr=10.211.0.0/16" - "--service-cidr=10.221.0.0/16" - "--write-kubeconfig-mode 0640" - "--write-kubeconfig-group kubeconfig" - "--resolv-conf=/etc/resolv.conf" - "--tls-san ${config.networking.hostName}.home" - "--tls-san ${config.networking.hostName}.thehellings.lan" - "--tls-san ${config.networking.hostName}.shire-zebra.ts.net" - ]; - serverAddr = lib.mkIf (config.networking.hostName != "isaiah") "https://isaiah.home:6443"; + services = { + k3s = { + enable = true; + role = if cfg.agentOnly then "agent" else "server"; + tokenFile = config.age.secrets.kubernetesToken.path; + extraFlags = [ + "--cluster-cidr=10.211.0.0/16" + "--service-cidr=10.221.0.0/16" + "--write-kubeconfig-mode 0640" + "--write-kubeconfig-group kubeconfig" + "--resolv-conf=/etc/resolv.conf" + "--tls-san ${config.networking.hostName}.home" + "--tls-san ${config.networking.hostName}.thehellings.lan" + "--tls-san ${config.networking.hostName}.shire-zebra.ts.net" + ]; + serverAddr = lib.mkIf (config.networking.hostName != "isaiah") "https://isaiah.home:6443"; + }; + keepalived = + let + ip = (builtins.head config.networking.interfaces."${cfg.vipInterface}".ipv4.addresses).address; + in + { + enable = true; + openFirewall = true; + vrrpInstances.kubernetes = { + interface = cfg.vipInterface; + priority = cfg.priority; + state = if (config.networking.hostName == "isaiah") then "MASTER" else "BACKUP"; + virtualIps = [ + { + addr = "10.42.5.1/16"; + dev = cfg.vipInterface; + } + ]; + virtualRouterId = 77; + unicastPeers = lib.filter (v: v != ip) [ + "10.42.1.6" + "10.42.1.8" + "10.42.1.13" + ]; + unicastSrcIp = ip; + extraConfig = '' + advert_int 1 + ''; + }; + }; }; users = { From c7e96d1f29d75554e4c6d04aa5452a8e4887d91d Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 3 Jul 2025 01:36:59 -0500 Subject: [PATCH 036/124] Enable Longhorn at last Enable the iscsi services on the local hosts Enable special NixOS style Longhorn workarounds Enable Longhorn in Kubernetes, as well Update host names to point at Longhorn Expose Longhorn UI and secrets --- hosts/genesis/net/hosts | 4 +- hosts/isaiah/hardware-configuration.nix | 5 + hosts/jeremiah/hardware-configuration.nix | 5 + manifests/apply.sh | 17 ++++ manifests/helm/kustomization.yaml | 2 + manifests/helm/kyverno.yaml | 40 ++++++++ manifests/helm/longhorn.yaml | 115 ++++++++++++++++++++++ manifests/secrets/kustomization.yaml | 1 + manifests/secrets/longhorn.yaml | 33 +++++++ modules/nixos/kubernetes.nix | 6 ++ 10 files changed, 226 insertions(+), 2 deletions(-) create mode 100644 manifests/helm/kyverno.yaml create mode 100644 manifests/helm/longhorn.yaml create mode 100644 manifests/secrets/longhorn.yaml diff --git a/hosts/genesis/net/hosts b/hosts/genesis/net/hosts index 5228fd0..157a86c 100644 --- a/hosts/genesis/net/hosts +++ b/hosts/genesis/net/hosts @@ -24,7 +24,7 @@ 10.42.4.3 git gitlab git.thehellings.lan gitlab.thehellings.lan # VIP -10.42.5.1 pgadmin.cluter postgres.cluster matrix.cluster +10.42.5.1 longhorn.cluster matrix.cluster pgadmin.cluter postgres.cluster # IPMI 10.42.100.6 isaiahbmc isaiahbmc.thehellings.lan @@ -36,7 +36,7 @@ 100.88.91.27 genesis.home smart.home zwave.home nixcache.home gitcache.home dashy.home uptime.home speed.home 100.91.131.66 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan 100.68.203.1 hosea.home hosea.shire-zebra.ts.net -100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes postgres.kubernetes +100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes postgres.kubernetes longhorn.kubernetes 100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes 100.90.74.19 zeke.home 100.115.57.8 linode.home diff --git a/hosts/isaiah/hardware-configuration.nix b/hosts/isaiah/hardware-configuration.nix index 58cdcef..9c6d38e 100644 --- a/hosts/isaiah/hardware-configuration.nix +++ b/hosts/isaiah/hardware-configuration.nix @@ -46,6 +46,11 @@ fsType = "btrfs"; }; + fileSystems."/var/lib/longhorn" = { + device = "/dev/disk/by-uuid/b9f5ace7-d224-4aff-8770-d5a9d22be2ae"; + fsType = "xfs"; + }; + swapDevices = [ ]; # Enables DHCP on each ethernet and wireless interface. In case of scripted networking diff --git a/hosts/jeremiah/hardware-configuration.nix b/hosts/jeremiah/hardware-configuration.nix index c0c7635..e67f5ce 100644 --- a/hosts/jeremiah/hardware-configuration.nix +++ b/hosts/jeremiah/hardware-configuration.nix @@ -33,6 +33,11 @@ fsType = "vfat"; }; + fileSystems."/var/lib/longhorn" = { + device = "/dev/disk/by-uuid/1c896717-4a01-4136-825d-6c0160a78256"; + fsType = "xfs"; + }; + swapDevices = [ ]; # Enables DHCP on each ethernet and wireless interface. In case of scripted networking diff --git a/manifests/apply.sh b/manifests/apply.sh index 9ef3d4c8..af84718 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -6,9 +6,26 @@ SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )" # Change to the script directory cd "$SCRIPT_DIR" +# First, label the nodes to control Longhorn rollout +for n in isaiah jeremiah zeke; do + kubectl label nodes "${n}" "node.longhorn.io/create-default-disk=config" +done +# Now, configure longhorn settings for each node +kubectl annotate nodes isaiah 'node.longhorn.io/default-disks-config=[ + { "path": "/var/lib/longhorn", "allowScheduling" : true } +]' +kubectl annotate nodes jeremiah 'node.longhorn.io/default-disks-config=[ + { "path": "/var/lib/longhorn", "allowScheduling" : true } +]' +kubectl annotate nodes zeke 'node.longhorn.io/default-disks-config=[ + { "path": "/var/lib/longhorn", "allowScheduling" : true } +]' + kubectl apply -k namespaces kubectl apply -f helm/flux.yaml sleep 5 +kubectl apply -f helm/kyverno.yaml +sleep 15 kubectl apply -k helm sleep 5 kubectl apply -k . diff --git a/manifests/helm/kustomization.yaml b/manifests/helm/kustomization.yaml index c6ae679..5f37ea3 100644 --- a/manifests/helm/kustomization.yaml +++ b/manifests/helm/kustomization.yaml @@ -1,5 +1,7 @@ resources: - flux.yaml + - kyverno.yaml # Needed to configure Longhorn + - longhorn.yaml # Needed for storage - traefik.yaml - external-secrets.yaml - cloudnative-pg.yaml diff --git a/manifests/helm/kyverno.yaml b/manifests/helm/kyverno.yaml new file mode 100644 index 0000000..bce3318 --- /dev/null +++ b/manifests/helm/kyverno.yaml @@ -0,0 +1,40 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: kyverno-system +--- +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository +metadata: + name: kyverno + namespace: kyverno-system +spec: + interval: "24h" + url: "https://kyverno.github.io/kyverno/" +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: kyverno + namespace: kyverno-system +spec: + interval: 10m + chart: + spec: + chart: kyverno + version: "3.4.4" + sourceRef: + kind: HelmRepository + name: kyverno + interval: "1h" + values: + admissionController: + replicas: 3 + backgroundController: + replicas: 3 + cleanupController: + replicas: 2 + reportsController: + replicas: 2 + crds: + install: true diff --git a/manifests/helm/longhorn.yaml b/manifests/helm/longhorn.yaml new file mode 100644 index 0000000..8b0bf12 --- /dev/null +++ b/manifests/helm/longhorn.yaml @@ -0,0 +1,115 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: longhorn-system +--- +apiVersion: source.toolkit.fluxcd.io/v1 +kind: HelmRepository +metadata: + name: longhorn + namespace: longhorn-system +spec: + interval: "24h" + url: "https://charts.longhorn.io" +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: longhorn + namespace: longhorn-system +spec: + interval: 10m + chart: + spec: + chart: longhorn + version: "1.9.0" + sourceRef: + kind: HelmRepository + name: longhorn + interval: "1h" + values: + defaultSettings: + createDefaultDiskLabeledNodes: true +--- +apiVersion: v1 +kind: ConfigMap +metadata: + name: longhorn-custom-path + namespace: longhorn-system +data: + PATH: /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/run/wrappers/bin:/nix/var/nix/profiles/default/bin:/run/current-system/sw/bin +--- +apiVersion: kyverno.io/v1 +kind: ClusterPolicy +metadata: + name: add-host-path-to-longhorn + annotations: + policies.kyverno.io/title: Add Environment Variables from ConfigMap + policies.kyverno.io/subject: Pod + policies.kyverno.io/category: Other + policies.kyverno.io/description: >- + Longhorn invokes executables on the host system, and needs + to be aware of the host systems PATH. This modifies all + deployments such that the PATH is explicitly set to support + NixOS based systems. +spec: + rules: + - name: add-env-vars + match: + resources: + kinds: + - Pod + namespaces: + - longhorn-system + mutate: + patchStrategicMerge: + spec: + initContainers: + - (name): "*" + envFrom: + - configMapRef: + name: longhorn-custom-path + containers: + - (name): "*" + envFrom: + - configMapRef: + name: longhorn-custom-path +--- +apiVersion: traefik.io/v1alpha1 +kind: Middleware +metadata: + namespace: longhorn-system + name: basic-auth +spec: + basicAuth: + realm: Traefik + secret: longhorn-ui +--- +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: longhorn-ingress + namespace: longhorn-system + annotations: + ingressClassName: traefik + traefik.ingress.kubernetes.io/router.middlewares: longhorn-system-basic-auth@kubernetescrd + # Set body size to 10G to allow uploading large things + traefik.ingress.kubernetes.io/buffering: | + maxrequestbodybytes: 10000000000 + memrequestbodybytes: 20000000000 +spec: + ingressClassName: traefik + rules: + - &host + host: longhorn.cluster + http: + paths: + - pathType: Prefix + path: "/" + backend: + service: + name: longhorn-frontend + port: + number: 80 + - <<: *host + host: longhorn.kubernetes diff --git a/manifests/secrets/kustomization.yaml b/manifests/secrets/kustomization.yaml index e132e9f..ba8494d 100644 --- a/manifests/secrets/kustomization.yaml +++ b/manifests/secrets/kustomization.yaml @@ -4,3 +4,4 @@ resources: - postgres-user-matrix.yaml - k3sbackup.yaml - gitlab-runner.yaml + - longhorn.yaml diff --git a/manifests/secrets/longhorn.yaml b/manifests/secrets/longhorn.yaml new file mode 100644 index 0000000..28d7402 --- /dev/null +++ b/manifests/secrets/longhorn.yaml @@ -0,0 +1,33 @@ +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: longhorn-ui + namespace: longhorn-system +spec: + target: + name: longhorn-ui + deletionPolicy: Delete + template: + type: kubernetes.io/basic-auth + data: + username: |- + {{ .username }} + password: |- + {{ .password }} + data: + - secretKey: username + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: cbf2bf72-c129-437a-8a75-b30f005d29ec + property: username + - secretKey: password + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: cbf2bf72-c129-437a-8a75-b30f005d29ec + property: password diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index cd0b647..d88a859 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -43,6 +43,8 @@ in pkgs.kubernetes-helm pkgs.kustomize pkgs.k9s + pkgs.openiscsi + pkgs.nfs-utils # Needed for Longhorn ]; networking.firewall = { @@ -111,6 +113,10 @@ in ''; }; }; + openiscsi = { + enable = true; + name = "${config.networking.hostName}-initiatorhost"; + }; }; users = { From 211270bc4c86c8c588321cdc195f6ae5e504718b Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 3 Jul 2025 21:40:11 -0500 Subject: [PATCH 037/124] Bookmark updates Combine SubTo and REI Add Longhorn --- modules/hm/gui/bookmarks.nix | 59 +++++++++++++++++++++--------------- 1 file changed, 34 insertions(+), 25 deletions(-) diff --git a/modules/hm/gui/bookmarks.nix b/modules/hm/gui/bookmarks.nix index ace7be0..deb0c32 100644 --- a/modules/hm/gui/bookmarks.nix +++ b/modules/hm/gui/bookmarks.nix @@ -183,31 +183,6 @@ } ]; } - { - name = "SubTo"; - bookmarks = [ - { - name = "Kajabi"; - url = "https://www.subtocourse.com/login"; - } - { - name = "SubTo Fund"; - url = "https://frontend.koreconx.com/auth/login"; - } - { - name = "Creive Title"; - url = "https://getcreativetitle.com/"; - } - { - name = "REI Scripts"; - url = "https://reiconveyorbelt.com/no-excuses/"; - } - { - name = "Ellis foreclosures"; - url = "https://co.ellis.tx.us/Archive.aspx?AMID=60"; - } - ]; - } { name = "Tools"; bookmarks = [ @@ -228,6 +203,15 @@ } ]; } + { + name = "Kubernetes"; + bookmarks = [ + { + name = "Longhorn"; + url = "http://longhorn.kubernetes"; + } + ]; + } { name = "PGAdmin4"; url = "http://pgadmin.kubernetes/"; @@ -257,6 +241,31 @@ name = "Door Loop"; url = "https://btrgpm.app.doorloop.com/home"; } + { + name = "SubTo"; + bookmarks = [ + { + name = "Kajabi"; + url = "https://www.subtocourse.com/login"; + } + { + name = "SubTo Fund"; + url = "https://frontend.koreconx.com/auth/login"; + } + { + name = "Creive Title"; + url = "https://getcreativetitle.com/"; + } + { + name = "REI Scripts"; + url = "https://reiconveyorbelt.com/no-excuses/"; + } + { + name = "Ellis foreclosures"; + url = "https://co.ellis.tx.us/Archive.aspx?AMID=60"; + } + ]; + } ]; } { From fea1a7642c64e93d6bf7d7873d03d0ddd7f40b15 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 7 Jul 2025 21:48:47 -0500 Subject: [PATCH 038/124] Enable Immich Kubernetes files to stand up Immich, including Redis, a separate Postgres cluster, and more --- hosts/genesis/net/hosts | 4 +- manifests/apply.sh | 22 +++++-- manifests/helm/cloudnative-pg.yaml | 33 ---------- manifests/helm/kustomization.yaml | 1 - manifests/helm/longhorn.yaml | 32 ++++++++++ manifests/immich/apply.sh | 23 +++++++ manifests/immich/database.yaml | 74 ++++++++++++++++++++++ manifests/immich/ingress.yaml | 26 ++++++++ manifests/immich/kustomization.yaml | 6 ++ manifests/immich/namespace.yaml | 4 ++ manifests/immich/postgres-user-secret.yaml | 67 ++++++++++++++++++++ manifests/immich/pvc.yaml | 29 +++++++++ manifests/immich/values-redis.yaml | 8 +++ manifests/immich/values.yaml | 46 ++++++++++++++ manifests/kustomization.yaml | 2 + manifests/pvc/kustomization.yaml | 2 + manifests/secrets/kustomization.yaml | 1 + manifests/values/cnpg.yaml | 3 + 18 files changed, 341 insertions(+), 42 deletions(-) delete mode 100644 manifests/helm/cloudnative-pg.yaml create mode 100755 manifests/immich/apply.sh create mode 100644 manifests/immich/database.yaml create mode 100644 manifests/immich/ingress.yaml create mode 100644 manifests/immich/kustomization.yaml create mode 100644 manifests/immich/namespace.yaml create mode 100644 manifests/immich/postgres-user-secret.yaml create mode 100644 manifests/immich/pvc.yaml create mode 100644 manifests/immich/values-redis.yaml create mode 100644 manifests/immich/values.yaml create mode 100644 manifests/pvc/kustomization.yaml create mode 100644 manifests/values/cnpg.yaml diff --git a/hosts/genesis/net/hosts b/hosts/genesis/net/hosts index 157a86c..00c6b9e 100644 --- a/hosts/genesis/net/hosts +++ b/hosts/genesis/net/hosts @@ -24,7 +24,7 @@ 10.42.4.3 git gitlab git.thehellings.lan gitlab.thehellings.lan # VIP -10.42.5.1 longhorn.cluster matrix.cluster pgadmin.cluter postgres.cluster +10.42.5.1 longhorn.cluster matrix.cluster pgadmin.cluter postgres.cluster immich.cluster # IPMI 10.42.100.6 isaiahbmc isaiahbmc.thehellings.lan @@ -37,7 +37,7 @@ 100.91.131.66 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan 100.68.203.1 hosea.home hosea.shire-zebra.ts.net 100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes postgres.kubernetes longhorn.kubernetes -100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes +100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes immich.kubernetes 100.90.74.19 zeke.home 100.115.57.8 linode.home 100.65.5.38 matrix.home matrix.shire-zebra.ts.net diff --git a/manifests/apply.sh b/manifests/apply.sh index af84718..21f056a 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -11,14 +11,14 @@ for n in isaiah jeremiah zeke; do kubectl label nodes "${n}" "node.longhorn.io/create-default-disk=config" done # Now, configure longhorn settings for each node -kubectl annotate nodes isaiah 'node.longhorn.io/default-disks-config=[ - { "path": "/var/lib/longhorn", "allowScheduling" : true } +kubectl annotate nodes --overwrite isaiah 'node.longhorn.io/default-disks-config=[ + { "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]} ]' -kubectl annotate nodes jeremiah 'node.longhorn.io/default-disks-config=[ - { "path": "/var/lib/longhorn", "allowScheduling" : true } +kubectl annotate nodes --overwrite jeremiah 'node.longhorn.io/default-disks-config=[ + { "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]} ]' -kubectl annotate nodes zeke 'node.longhorn.io/default-disks-config=[ - { "path": "/var/lib/longhorn", "allowScheduling" : true } +kubectl annotate nodes --overwrite zeke 'node.longhorn.io/default-disks-config=[ + { "path": "/var/lib/longhorn", "allowScheduling" : trues, "tags": ["ssd", "fast"]} ]' kubectl apply -k namespaces @@ -29,3 +29,13 @@ sleep 15 kubectl apply -k helm sleep 5 kubectl apply -k . +sleep 5 +# https://cloudnative-pg.io +helm repo add cnpg https://cloudnative-pg.github.io/charts/ +helm upgrade --install cnpg \ + --create-namespace --namespace cnpg-system \ + cnpg/cloudnative-pg \ + -f values/cnpg.yaml \ + --wait + +./immich/apply.sh diff --git a/manifests/helm/cloudnative-pg.yaml b/manifests/helm/cloudnative-pg.yaml deleted file mode 100644 index 46fe07d..0000000 --- a/manifests/helm/cloudnative-pg.yaml +++ /dev/null @@ -1,33 +0,0 @@ -apiVersion: v1 -kind: Namespace -metadata: - name: cnpg-system ---- -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository -metadata: - name: cloudnative-pg - namespace: cnpg-system -spec: - interval: "24h" - url: "https://cloudnative-pg.github.io/charts/" ---- -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: cnpg - namespace: cnpg-system -spec: - interval: 10m - chart: - spec: - chart: cloudnative-pg - version: "0.23.2" - sourceRef: - kind: HelmRepository - name: cloudnative-pg - interval: "1h" - values: - crds: - create: true - includeCRDs: true diff --git a/manifests/helm/kustomization.yaml b/manifests/helm/kustomization.yaml index 5f37ea3..531baaf 100644 --- a/manifests/helm/kustomization.yaml +++ b/manifests/helm/kustomization.yaml @@ -4,4 +4,3 @@ resources: - longhorn.yaml # Needed for storage - traefik.yaml - external-secrets.yaml - - cloudnative-pg.yaml diff --git a/manifests/helm/longhorn.yaml b/manifests/helm/longhorn.yaml index 8b0bf12..e72e098 100644 --- a/manifests/helm/longhorn.yaml +++ b/manifests/helm/longhorn.yaml @@ -113,3 +113,35 @@ spec: number: 80 - <<: *host host: longhorn.kubernetes +--- +apiVersion: storage.k8s.io/v1 +kind: StorageClass +metadata: + name: longhorn-default +provisioner: driver.longhorn.io +allowVolumeExpansion: true +reclaimPolicy: Delete +volumeBindingMode: Immediate +parameters: + backupTargetName: default + numberOfReplicas: "2" + staleReplicaTimeout: "2880" + fromBackup: "" + fsType: ext4 + diskSelector: "hdd,large" +--- +apiVersion: storage.k8s.io/v1 +kind: StorageClass +metadata: + name: longhorn-fast +provisioner: driver.longhorn.io +allowVolumeExpansion: true +reclaimPolicy: Delete +volumeBindingMode: Immediate +parameters: + backupTargetName: default + numberOfReplicas: "1" + staleReplicaTimeout: "2880" + fromBackup: "" + fsType: ext4 + diskSelector: "ssd,fast" diff --git a/manifests/immich/apply.sh b/manifests/immich/apply.sh new file mode 100755 index 0000000..03213a4 --- /dev/null +++ b/manifests/immich/apply.sh @@ -0,0 +1,23 @@ +#!/usr/bin/env bash + + +# Get the directory where the script is located +SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )" + +# Change to the script directory +cd "$SCRIPT_DIR" + +kubectl apply -k "$SCRIPT_DIR" + +# https://www.dragonflydb.io/guides/redis-kubernetes +# Deploys into immich namespace, directly, in order to allow the password to be +# accessed by the immich installer +helm upgrade --install --create-namespace --namespace immich redis \ + oci://registry-1.docker.io/bitnamicharts/redis \ + -f "${SCRIPT_DIR}/values-redis.yaml" \ + --wait +# https://github.com/immich-app/immich-charts/tree/main +helm upgrade --install --create-namespace --namespace immich immich \ + oci://ghcr.io/immich-app/immich-charts/immich \ + -f "${SCRIPT_DIR}/values.yaml" \ + --wait diff --git a/manifests/immich/database.yaml b/manifests/immich/database.yaml new file mode 100644 index 0000000..46c0bed --- /dev/null +++ b/manifests/immich/database.yaml @@ -0,0 +1,74 @@ +apiVersion: postgresql.cnpg.io/v1 +kind: Cluster +metadata: + namespace: db + name: pgvector +spec: + imageName: "ghcr.io/tensorchord/cloudnative-pgvecto.rs:16-v0.3.0" + instances: 1 + storage: + size: 10Gi + primaryUpdateStrategy: unsupervised + postgresql: + shared_preload_libraries: + - "vectors.so" + + bootstrap: + initdb: + database: immich + owner: immich + secret: + name: postgres-user-immich + dataChecksums: true + postInitApplicationSQL: + - ALTER SYSTEM SET search_path TO "$user", public, vectors; + - SET search_path TO "$user", public, vectors; + - CREATE EXTENSION IF NOT EXISTS "vectors"; + - CREATE EXTENSION IF NOT EXISTS "cube"; + - CREATE EXTENSION IF NOT EXISTS "earthdistance"; + - ALTER SCHEMA vectors OWNER TO "immich"; + - GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA vectors TO "immich"; + - GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO "immich"; + managed: + roles: + - name: immich + ensure: present + comment: Immich DB user + login: true + superuser: false + passwordSecret: + name: postgres-user-immich + backup: + retentionPolicy: "30d" + barmanObjectStore: + destinationPath: "s3://k3sbackup/pgvector" + endpointURL: "http://s3.thehellings.lan:9000/" + s3Credentials: + accessKeyId: + name: k3sbackup + key: username + secretAccessKey: + name: k3sbackup + key: password + wal: + compression: gzip +--- +apiVersion: postgresql.cnpg.io/v1 +kind: Database +metadata: + namespace: db + name: database-immich +spec: + name: immich + owner: immich + cluster: + name: pgvector + extensions: + - name: vectors + ensure: present + - name: vectorchord + ensure: present + - name: cube + ensure: present + - name: earthdistance + ensure: present diff --git a/manifests/immich/ingress.yaml b/manifests/immich/ingress.yaml new file mode 100644 index 0000000..9ccb756 --- /dev/null +++ b/manifests/immich/ingress.yaml @@ -0,0 +1,26 @@ +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + namespace: immich + name: immich + annotations: + ingressClassName: traefik + # Set body size to 10G to allow uploading large things + traefik.ingress.kubernetes.io/buffering: | + maxrequestbodybytes: 10000000000 + memrequestbodybytes: 20000000000 +spec: + rules: + - &host + host: immich.kubernetes + http: + paths: + - path: / + pathType: Prefix + backend: + service: + name: immich-server + port: + name: http + - <<: *host + host: immich.thehellings.com diff --git a/manifests/immich/kustomization.yaml b/manifests/immich/kustomization.yaml new file mode 100644 index 0000000..db99467 --- /dev/null +++ b/manifests/immich/kustomization.yaml @@ -0,0 +1,6 @@ +resources: + - namespace.yaml + - postgres-user-secret.yaml + - database.yaml + - pvc.yaml + - ingress.yaml diff --git a/manifests/immich/namespace.yaml b/manifests/immich/namespace.yaml new file mode 100644 index 0000000..c796392 --- /dev/null +++ b/manifests/immich/namespace.yaml @@ -0,0 +1,4 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: immich diff --git a/manifests/immich/postgres-user-secret.yaml b/manifests/immich/postgres-user-secret.yaml new file mode 100644 index 0000000..1e100bf --- /dev/null +++ b/manifests/immich/postgres-user-secret.yaml @@ -0,0 +1,67 @@ +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: postgres-user-immich + namespace: db +spec: + target: + name: postgres-user-immich + deletionPolicy: Delete + template: + type: Opaque + data: + username: |- + {{ .username }} + password: |- + {{ .password }} + data: + - secretKey: username + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 5ce63e26-dd7f-46d4-b7ed-b310002ef93f + property: username + - secretKey: password + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 5ce63e26-dd7f-46d4-b7ed-b310002ef93f + property: password +--- +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: postgres-user-immich + namespace: immich +spec: + target: + name: postgres-user-immich + deletionPolicy: Delete + template: + type: Opaque + data: + username: |- + {{ .username }} + password: |- + {{ .password }} + data: + - secretKey: username + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 5ce63e26-dd7f-46d4-b7ed-b310002ef93f + property: username + - secretKey: password + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 5ce63e26-dd7f-46d4-b7ed-b310002ef93f + property: password diff --git a/manifests/immich/pvc.yaml b/manifests/immich/pvc.yaml new file mode 100644 index 0000000..76563de --- /dev/null +++ b/manifests/immich/pvc.yaml @@ -0,0 +1,29 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + namespace: immich + name: immich-storage +spec: + storageClassName: longhorn-default + volumeName: immich-storage + resources: + requests: + storage: 250Gi + accessModes: + - ReadWriteOnce +--- +#apiVersion: v1 +#kind: PersistentVolume +#metadata: + #namespace: immich + #name: immich-storage +#spec: + #storageClassName: longhorn-default + #capacity: + #storage: 250Gi + #volumeMode: Filesystem + #accessModes: + #- ReadWriteOnce + #csi: + #driver: driver.longhorn.io + #volumeHandle: immich-storage diff --git a/manifests/immich/values-redis.yaml b/manifests/immich/values-redis.yaml new file mode 100644 index 0000000..4991c5d --- /dev/null +++ b/manifests/immich/values-redis.yaml @@ -0,0 +1,8 @@ +# https://github.com/bitnami/charts/blob/main/bitnami/redis/values.yaml +# https://github.com/bitnami/charts/tree/main/bitnami/redis +architecture: standalone +global: + defaultStorageClass: longhorn-default +master: + persistence: + storageClass: longhorn-default diff --git a/manifests/immich/values.yaml b/manifests/immich/values.yaml new file mode 100644 index 0000000..64142bb --- /dev/null +++ b/manifests/immich/values.yaml @@ -0,0 +1,46 @@ +# https://github.com/immich-app/immich-charts/blob/main/charts/immich/values.yaml +env: + DB_HOSTNAME: pgvector-rw.db.svc.cluster.local + DB_DATABASE_NAME: immich + DB_USERNAME: + valueFrom: + secretKeyRef: + name: postgres-user-immich + key: username + DB_PASSWORD: + valueFrom: + secretKeyRef: + name: postgres-user-immich + key: password + REDIS_HOSTNAME: redis-master + REDIS_PASSWORD: + valueFrom: + secretKeyRef: + name: redis + key: redis-password +image: + tag: "v1.135.3" +immich: + persistence: + library: + existingClaim: immich-storage +server: + ingress: + main: + enabled: true + annogations: + ingressClassName: traefik + # Set body size to 10G to allow uploading large things + traefik.ingress.kubernetes.io/buffering: | + maxrequestbodybytes: 10000000000 + memrequestbodybytes: 20000000000 + hosts: + - host: immich.cluster + paths: + - path: "/" +machine-learning: + persistence: + cache: + type: pvc + storageClass: longhorn-default + size: 25Gi diff --git a/manifests/kustomization.yaml b/manifests/kustomization.yaml index d30f511..7f1876f 100644 --- a/manifests/kustomization.yaml +++ b/manifests/kustomization.yaml @@ -1,8 +1,10 @@ resources: - namespaces + - pvc - helm - bitwarden - secrets - databases - matrix - gitlab-runner + - immich diff --git a/manifests/pvc/kustomization.yaml b/manifests/pvc/kustomization.yaml new file mode 100644 index 0000000..2a5138b --- /dev/null +++ b/manifests/pvc/kustomization.yaml @@ -0,0 +1,2 @@ +resources: + - immich.yaml diff --git a/manifests/secrets/kustomization.yaml b/manifests/secrets/kustomization.yaml index ba8494d..502d47e 100644 --- a/manifests/secrets/kustomization.yaml +++ b/manifests/secrets/kustomization.yaml @@ -2,6 +2,7 @@ resources: - postgres-user-gitlab.yaml - postgres-user-pgadmin.yaml - postgres-user-matrix.yaml + - postgres-user-immich.yaml - k3sbackup.yaml - gitlab-runner.yaml - longhorn.yaml diff --git a/manifests/values/cnpg.yaml b/manifests/values/cnpg.yaml new file mode 100644 index 0000000..991e377 --- /dev/null +++ b/manifests/values/cnpg.yaml @@ -0,0 +1,3 @@ +crds: + create: true +includeCRDs: true From c40f890c31df938a6fd905e68c6bee6db4f4c6de Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 7 Jul 2025 21:50:34 -0500 Subject: [PATCH 039/124] Add some dns tools --- home/baseline/tools.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index cbb18ce..8d8598d 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -1,6 +1,8 @@ { pkgs, ... }: { home.packages = with pkgs; [ + dig + dnsutils jqp iamb impala From 9ffff4adcb2b403b533e9b279dbe7d59eab286cc Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 11 Jul 2025 10:48:17 -0400 Subject: [PATCH 040/124] Impala is Linux-only --- home/baseline/tools.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index 8d8598d..e41017e 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -1,13 +1,14 @@ -{ pkgs, ... }: +{ lib, pkgs, ... }: { home.packages = with pkgs; [ dig dnsutils jqp iamb - impala rainfrog tenere wiki-tui - ]; + ] ++ (lib.optionals pkgs.stdenv.hostPlatform.isLinux [ + impala + ]); } From e4d726e6650df2fe8af2ad913e923ee5a1302956 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 24 Jul 2025 09:55:27 -0500 Subject: [PATCH 041/124] Update pins --- flake.lock | 163 ++++++++++++++----------------------- overlays/xonsh-apipenv.nix | 3 + 2 files changed, 65 insertions(+), 101 deletions(-) diff --git a/flake.lock b/flake.lock index c910ced..cd39408 100644 --- a/flake.lock +++ b/flake.lock @@ -31,11 +31,11 @@ "nixpkgs-unstable": "nixpkgs-unstable" }, "locked": { - "lastModified": 1749652690, - "narHash": "sha256-qLwBEXlGY2pLNPhPNpeOE0DNC1luovTYE3ZDPMyMPXc=", + "lastModified": 1751530600, + "narHash": "sha256-9YzlL/TIcVmuqXbN5VKEjzLAUO189h0DOBq9eNGgpaQ=", "owner": "fort-nix", "repo": "nix-bitcoin", - "rev": "ac1344fb6d91e2af219803eaaa67d1d974666156", + "rev": "e2ca2e496769a787a06c068acb43cb077c1fdc8c", "type": "github" }, "original": { @@ -74,11 +74,11 @@ ] }, "locked": { - "lastModified": 1750618568, - "narHash": "sha256-w9EG5FOXrjXGfbqCcQg9x1lMnTwzNDW5BMXp8ddy15E=", + "lastModified": 1751313918, + "narHash": "sha256-HsJM3XLa43WpG+665aGEh8iS8AfEwOIQWk3Mke3e7nk=", "owner": "lnl7", "repo": "nix-darwin", - "rev": "1dd19f19e4b53a1fd2e8e738a08dd5fe635ec7e5", + "rev": "e04a388232d9a6ba56967ce5b53a8a6f713cdfcf", "type": "github" }, "original": { @@ -166,11 +166,11 @@ "nixpkgs-lib": "nixpkgs-lib" }, "locked": { - "lastModified": 1749398372, - "narHash": "sha256-tYBdgS56eXYaWVW3fsnPQ/nFlgWi/Z2Ymhyu21zVM98=", + "lastModified": 1753121425, + "narHash": "sha256-TVcTNvOeWWk1DXljFxVRp+E0tzG1LhrVjOGGoMHuXio=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "9305fe4e5c2a6fcf5ba6a3ff155720fbe4076569", + "rev": "644e0fc48951a860279da645ba77fe4a6e814c5e", "type": "github" }, "original": { @@ -187,11 +187,11 @@ ] }, "locked": { - "lastModified": 1749398372, - "narHash": "sha256-tYBdgS56eXYaWVW3fsnPQ/nFlgWi/Z2Ymhyu21zVM98=", + "lastModified": 1751413152, + "narHash": "sha256-Tyw1RjYEsp5scoigs1384gIg6e0GoBVjms4aXFfRssQ=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "9305fe4e5c2a6fcf5ba6a3ff155720fbe4076569", + "rev": "77826244401ea9de6e3bac47c2db46005e1f30b5", "type": "github" }, "original": { @@ -226,11 +226,11 @@ "nixpkgs-lib": "nixpkgs-lib_2" }, "locked": { - "lastModified": 1749398372, - "narHash": "sha256-tYBdgS56eXYaWVW3fsnPQ/nFlgWi/Z2Ymhyu21zVM98=", + "lastModified": 1751413152, + "narHash": "sha256-Tyw1RjYEsp5scoigs1384gIg6e0GoBVjms4aXFfRssQ=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "9305fe4e5c2a6fcf5ba6a3ff155720fbe4076569", + "rev": "77826244401ea9de6e3bac47c2db46005e1f30b5", "type": "github" }, "original": { @@ -321,11 +321,11 @@ ] }, "locked": { - "lastModified": 1750798083, - "narHash": "sha256-DTCCcp6WCFaYXWKFRA6fiI2zlvOLCf5Vwx8+/0R8Wc4=", + "lastModified": 1753180535, + "narHash": "sha256-KEtlzMs2O7FDvciFtjk9W4hyau013Pj9qZNK9a0PxEc=", "owner": "nix-community", "repo": "home-manager", - "rev": "ff31a4677c1a8ae506aa7e003a3dba08cb203f82", + "rev": "847711c7ffa9944b0c5c39a8342ac8eb6a9f9abc", "type": "github" }, "original": { @@ -406,11 +406,11 @@ }, "nix-hardware": { "locked": { - "lastModified": 1750837715, - "narHash": "sha256-2m1ceZjbmgrJCZ2PuQZaK4in3gcg3o6rZ7WK6dr5vAA=", + "lastModified": 1753122741, + "narHash": "sha256-nFxE8lk9JvGelxClCmwuJYftbHqwnc01dRN4DVLUroM=", "owner": "nixos", "repo": "nixos-hardware", - "rev": "98236410ea0fe204d0447149537a924fb71a6d4f", + "rev": "cc66fddc6cb04ab479a1bb062f4d4da27c936a22", "type": "github" }, "original": { @@ -442,11 +442,11 @@ ] }, "locked": { - "lastModified": 1747663185, - "narHash": "sha256-Obh50J+O9jhUM/FgXtI3he/QRNiV9+J53+l+RlKSaAk=", + "lastModified": 1751903740, + "narHash": "sha256-PeSkNMvkpEvts+9DjFiop1iT2JuBpyknmBUs0Un0a4I=", "owner": "nix-community", "repo": "nixos-generators", - "rev": "ee07ba0d36c38e9915c55d2ac5a8fb0f05f2afcc", + "rev": "032decf9db65efed428afd2fa39d80f7089085eb", "type": "github" }, "original": { @@ -457,11 +457,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1749494155, - "narHash": "sha256-FG4DEYBpROupu758beabUk9lhrblSf5hnv84v1TLqMc=", + "lastModified": 1750969886, + "narHash": "sha256-zW/OFnotiz/ndPFdebpo3X0CrbVNf22n4DjN2vxlb58=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "88331c17ba434359491e8d5889cce872464052c2", + "rev": "a676066377a2fe7457369dd37c31fd2263b662f4", "type": "github" }, "original": { @@ -473,11 +473,11 @@ }, "nixpkgs-lib": { "locked": { - "lastModified": 1748740939, - "narHash": "sha256-rQaysilft1aVMwF14xIdGS3sj1yHlI6oKQNBRTF40cc=", + "lastModified": 1751159883, + "narHash": "sha256-urW/Ylk9FIfvXfliA1ywh75yszAbiTEVgpPeinFyVZo=", "owner": "nix-community", "repo": "nixpkgs.lib", - "rev": "656a64127e9d791a334452c6b6606d17539476e2", + "rev": "14a40a1d7fb9afa4739275ac642ed7301a9ba1ab", "type": "github" }, "original": { @@ -488,11 +488,11 @@ }, "nixpkgs-lib_2": { "locked": { - "lastModified": 1748740939, - "narHash": "sha256-rQaysilft1aVMwF14xIdGS3sj1yHlI6oKQNBRTF40cc=", + "lastModified": 1751159883, + "narHash": "sha256-urW/Ylk9FIfvXfliA1ywh75yszAbiTEVgpPeinFyVZo=", "owner": "nix-community", "repo": "nixpkgs.lib", - "rev": "656a64127e9d791a334452c6b6606d17539476e2", + "rev": "14a40a1d7fb9afa4739275ac642ed7301a9ba1ab", "type": "github" }, "original": { @@ -518,11 +518,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1749558678, - "narHash": "sha256-DUVAe8E2X2QM0dAnTGlTiqemMqUMMyIeCH7UeNo0g64=", + "lastModified": 1750994206, + "narHash": "sha256-3u6rEbIX9CN/5A5/mc3u0wIO1geZ0EhjvPBXmRDHqWM=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "a12f3a99614894502e73eb816e9e076b0ab05730", + "rev": "80d50fc87924c2a0d346372d242c27973cf8cdbf", "type": "github" }, "original": { @@ -565,11 +565,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1750741721, - "narHash": "sha256-Z0djmTa1YmnGMfE9jEe05oO4zggjDmxOGKwt844bUhE=", + "lastModified": 1752950548, + "narHash": "sha256-NS6BLD0lxOrnCiEOcvQCDVPXafX1/ek1dfJHX1nUIzc=", "owner": "nixos", "repo": "nixpkgs", - "rev": "4b1164c3215f018c4442463a27689d973cffd750", + "rev": "c87b95e25065c028d31a94f06a62927d18763fdf", "type": "github" }, "original": { @@ -597,11 +597,11 @@ }, "nixunstable": { "locked": { - "lastModified": 1750741721, - "narHash": "sha256-Z0djmTa1YmnGMfE9jEe05oO4zggjDmxOGKwt844bUhE=", + "lastModified": 1752950548, + "narHash": "sha256-NS6BLD0lxOrnCiEOcvQCDVPXafX1/ek1dfJHX1nUIzc=", "owner": "nixos", "repo": "nixpkgs", - "rev": "4b1164c3215f018c4442463a27689d973cffd750", + "rev": "c87b95e25065c028d31a94f06a62927d18763fdf", "type": "github" }, "original": { @@ -621,11 +621,11 @@ "systems": "systems_4" }, "locked": { - "lastModified": 1750879244, - "narHash": "sha256-ClV6rZbPnd5wIcBYNiCdrbhtSzY6dwPRA4Z/z1cFcyo=", + "lastModified": 1752976861, + "narHash": "sha256-59HcrqHfbSJUdmpzrAa9x8fW1PoS+ZGhCjL5k5HbyV8=", "owner": "nix-community", "repo": "nixvim", - "rev": "f0764db7212003520341ac10ddcee50e9c458a6f", + "rev": "0c50ed9349199219583cb1ed1a972d71e06039ec", "type": "github" }, "original": { @@ -638,15 +638,14 @@ "nurpkgs": { "inputs": { "flake-parts": "flake-parts_3", - "nixpkgs": "nixpkgs_3", - "treefmt-nix": "treefmt-nix" + "nixpkgs": "nixpkgs_3" }, "locked": { - "lastModified": 1750879289, - "narHash": "sha256-2kq9yVW4rMuidAqn0YWWt9B/5WsuzXPyoH46bQGN8rU=", + "lastModified": 1753197323, + "narHash": "sha256-XqeaKquaFebKMhyl7ty+OJaB91tmXstX5BZh/gRbKag=", "owner": "nix-community", "repo": "NUR", - "rev": "82688d18898c7f521cdaa8c4b6d182f34a2a1acd", + "rev": "6a546a5059e6b803b6bca4a2f8ecbf6729630339", "type": "github" }, "original": { @@ -678,22 +677,6 @@ "type": "github" } }, - "patched-nixpkgs": { - "locked": { - "lastModified": 1750677113, - "narHash": "sha256-hOLEPjPscArQiPm4+EPuVuvcXX7uhIx18gLvXrDS/5k=", - "owner": "TomaSajt", - "repo": "nixpkgs", - "rev": "27a4b311a7ea290aa2504019c8693b7dace8dab5", - "type": "github" - }, - "original": { - "owner": "TomaSajt", - "ref": "fetch-cargo-vendor-dup", - "repo": "nixpkgs", - "type": "github" - } - }, "proxmox": { "inputs": { "flake-compat": "flake-compat_2", @@ -702,11 +685,11 @@ "utils": "utils" }, "locked": { - "lastModified": 1750064469, - "narHash": "sha256-yaEzei8/2LBZL+h0iKO28eeP1Cvl5v0piAyakZfZL0s=", + "lastModified": 1751538533, + "narHash": "sha256-aNB6A0+azhP/Wt9fFQslHMeQHlTYoz8Y/1cI4XqzrP0=", "owner": "SaumonNet", "repo": "proxmox-nixos", - "rev": "8df841766fab6c15341577b6982ddd368be72113", + "rev": "bfe830d4d3fc055b8d157313a3ec2fa69ded5d4e", "type": "github" }, "original": { @@ -824,27 +807,6 @@ "type": "github" } }, - "treefmt-nix": { - "inputs": { - "nixpkgs": [ - "nurpkgs", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1733222881, - "narHash": "sha256-JIPcz1PrpXUCbaccEnrcUS8jjEb/1vJbZz5KkobyFdM=", - "owner": "numtide", - "repo": "treefmt-nix", - "rev": "49717b5af6f80172275d47a418c9719a31a78b53", - "type": "github" - }, - "original": { - "owner": "numtide", - "repo": "treefmt-nix", - "type": "github" - } - }, "utils": { "inputs": { "systems": "systems_5" @@ -869,11 +831,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1750817194, - "narHash": "sha256-9CCF4ANxZUXHwz74SeGQkFi4OYnm0BD2I3GeQvxMKPM=", + "lastModified": 1753150460, + "narHash": "sha256-q2dkvuIfEb5fWBF6TJePJbcP1hqxARAUddfPGVGvD38=", "owner": "nix-community", "repo": "nix-vscode-extensions", - "rev": "fc01ad517af163c76d4493c5959fc5c44244a97f", + "rev": "d13827556415f4050b510e9cfb9873c1ce9aaec4", "type": "github" }, "original": { @@ -890,11 +852,11 @@ ] }, "locked": { - "lastModified": 1749574455, - "narHash": "sha256-fm2/8KPOYvvIAnNVtjDlTt/My00lIbZQ+LMrfQIWVzs=", + "lastModified": 1752682362, + "narHash": "sha256-ZNIpqCG/CfhmV+TgIeyO/XbhDjSWpwWokHM44j0Mn0w=", "owner": "nix-community", "repo": "NixOS-WSL", - "rev": "917af390377c573932d84b5e31dd9f2c1b5c0f09", + "rev": "20001f9bf0aaf2b1c307e43a5eec8cf8f800fe14", "type": "github" }, "original": { @@ -908,15 +870,14 @@ "flake-parts": "flake-parts_4", "nixpkgs": [ "nixunstable" - ], - "patched-nixpkgs": "patched-nixpkgs" + ] }, "locked": { - "lastModified": 1750686425, - "narHash": "sha256-8GK4ofgwZFfHxMv/2nDcnIbkDd+3O5qI96kgGx8iczA=", + "lastModified": 1752421971, + "narHash": "sha256-bxzE0OeFcLPQSKtxTzMUBx9Y5cw4Ni3v2RIFvD38ctA=", "owner": "HPsaucii", "repo": "zed-editor-flake", - "rev": "4e8e32b58f3095116dd9404f0ea030173626eb15", + "rev": "fa1af347db694c06e6b927a4acf3e4c455c2ae37", "type": "github" }, "original": { diff --git a/overlays/xonsh-apipenv.nix b/overlays/xonsh-apipenv.nix index 5a132d5..e3676ed 100644 --- a/overlays/xonsh-apipenv.nix +++ b/overlays/xonsh-apipenv.nix @@ -4,11 +4,13 @@ fetchFromGitHub, toPythonModule, pipenv, + setuptools, }: buildPythonPackage rec { pname = "xonsh-apipenv"; version = "0.6.0"; + pyproject = true; src = fetchFromGitHub { owner = "greg-hellings"; @@ -18,6 +20,7 @@ buildPythonPackage rec { }; dependencies = [ (toPythonModule pipenv) ]; + build-system = [ setuptools ]; meta = with lib; { description = "Auto pipenv support for Xonsh"; From 54c8c6c529ebcd9a5519689cc77560af30c68a34 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 24 Jul 2025 09:56:04 -0500 Subject: [PATCH 042/124] Add podman to IVR --- darwin/hosts/ivr/default.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/darwin/hosts/ivr/default.nix b/darwin/hosts/ivr/default.nix index fcffb1d..79cebfa 100644 --- a/darwin/hosts/ivr/default.nix +++ b/darwin/hosts/ivr/default.nix @@ -19,6 +19,9 @@ in "mysql" "nushell" "poetry" + "podman" + "podman-compose" + "pytest" "qemu" ]; casks = [ @@ -32,6 +35,7 @@ in "microsoft-teams" "onlyoffice" "pgadmin4" + "podman-desktop" "tabby" "twine" "vagrant" From 1354eee354c6b9651bdca08bcdf94398af67d156 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 24 Jul 2025 09:56:18 -0500 Subject: [PATCH 043/124] Basic zellij configuration --- home/baseline/tools.nix | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index e41017e..e40f890 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -11,4 +11,28 @@ ] ++ (lib.optionals pkgs.stdenv.hostPlatform.isLinux [ impala ]); + + programs = { + zellij = { + enable = true; + attachExistingSession = true; + enableZshIntegration = pkgs.stdenv.hostPlatform.isDarwin; + settings = { + keybinds = { + normal._children = [ + { + bind = { + _args = [ "Ctrl b" ]; + _children = [ + { + SwitchToMode._args = [ "locked" ]; + } + ]; + }; + } + ]; + }; # /keybinds + }; # /settings + }; + }; } From 204e176ddc700c067af3dbb7e7b12307ce74c415 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 22 Jul 2025 09:45:56 -0500 Subject: [PATCH 044/124] Add bookmark --- modules/hm/gui/bookmarks.nix | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/modules/hm/gui/bookmarks.nix b/modules/hm/gui/bookmarks.nix index deb0c32..cbe88d0 100644 --- a/modules/hm/gui/bookmarks.nix +++ b/modules/hm/gui/bookmarks.nix @@ -237,10 +237,6 @@ { name = "REI"; bookmarks = [ - { - name = "Door Loop"; - url = "https://btrgpm.app.doorloop.com/home"; - } { name = "SubTo"; bookmarks = [ @@ -266,6 +262,14 @@ } ]; } + { + name = "Door Loop"; + url = "https://btrgpm.app.doorloop.com/home"; + } + { + name = "HELOC payoff calculator"; + url = "https://acceleratedstrategies.com/free-calculator/"; + } ]; } { From 2e8dcb7497644a5db74460663d7a57dab892e019 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 22 Jul 2025 09:46:44 -0500 Subject: [PATCH 045/124] Enable Graphene install on Exodus --- hosts/exodus/default.nix | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/hosts/exodus/default.nix b/hosts/exodus/default.nix index 3c6b83d..96a0826 100644 --- a/hosts/exodus/default.nix +++ b/hosts/exodus/default.nix @@ -41,6 +41,8 @@ networkmanager.enable = lib.mkForce true; }; + programs.adb.enable = true; + services = { fprintd.enable = true; fwupd = { @@ -53,5 +55,9 @@ oci-containers.backend = "podman"; }; - users.users.greg.extraGroups = [ "podman" ]; + users.users.greg.extraGroups = [ + "adbusers" + "kvm" + "podman" + ]; } From 1c5507ce8d68f013a96c3ef5d1eb6bfa4e95fb1d Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 22 Jul 2025 09:46:56 -0500 Subject: [PATCH 046/124] Install gitlab-runner on Zeke --- hosts/zeke/virt.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/hosts/zeke/virt.nix b/hosts/zeke/virt.nix index b1943be..8a7d448 100644 --- a/hosts/zeke/virt.nix +++ b/hosts/zeke/virt.nix @@ -98,6 +98,14 @@ in ''; }; }; + + gitlab-runner = { + serviceConfig = { + DevicePolicy = lib.mkForce "auto"; + User = "root"; + DynamicUser = lib.mkForce false; + }; + }; }; virtualisation = { From 8624902722dea34da7eb5e14d7a56c6762ef71bb Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 24 Jul 2025 12:54:48 -0500 Subject: [PATCH 047/124] Expose backup secrets to Longhorn --- manifests/secrets/longhorn.yaml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/manifests/secrets/longhorn.yaml b/manifests/secrets/longhorn.yaml index 28d7402..4c8f037 100644 --- a/manifests/secrets/longhorn.yaml +++ b/manifests/secrets/longhorn.yaml @@ -31,3 +31,31 @@ spec: remoteRef: key: cbf2bf72-c129-437a-8a75-b30f005d29ec property: password +--- +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: longhorn-minio + namespace: longhorn-system +spec: + target: + name: longhorn-minio + deletionPolicy: Delete + template: + type: Opaque + data: + AWS_ACCESS_KEY_ID: "{{ .username }}" + AWS_SECRET_ACCESS_KEY: "{{ .password }}" + AWS_ENDPOINTS: "http://s3.thehellings.lan:9000/" + secretStoreRef: + name: bitwarden-login + kind: ClusterSecretStore + data: + - secretKey: username + remoteRef: + key: 685b29c6-9264-4e60-ba4a-b2ea005a5d7b + property: username + - secretKey: password + remoteRef: + key: 685b29c6-9264-4e60-ba4a-b2ea005a5d7b + property: password From ffba523e68ab05dbd0cb75c26c5a86abc2e66de1 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 24 Jul 2025 12:55:24 -0500 Subject: [PATCH 048/124] Remove references to missing files --- manifests/pvc/kustomization.yaml | 2 -- manifests/secrets/kustomization.yaml | 1 - 2 files changed, 3 deletions(-) delete mode 100644 manifests/pvc/kustomization.yaml diff --git a/manifests/pvc/kustomization.yaml b/manifests/pvc/kustomization.yaml deleted file mode 100644 index 2a5138b..0000000 --- a/manifests/pvc/kustomization.yaml +++ /dev/null @@ -1,2 +0,0 @@ -resources: - - immich.yaml diff --git a/manifests/secrets/kustomization.yaml b/manifests/secrets/kustomization.yaml index 502d47e..ba8494d 100644 --- a/manifests/secrets/kustomization.yaml +++ b/manifests/secrets/kustomization.yaml @@ -2,7 +2,6 @@ resources: - postgres-user-gitlab.yaml - postgres-user-pgadmin.yaml - postgres-user-matrix.yaml - - postgres-user-immich.yaml - k3sbackup.yaml - gitlab-runner.yaml - longhorn.yaml From f77ded4b6e1f55cb7a20fe17c7a9436f9fb30b18 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 24 Jul 2025 12:55:43 -0500 Subject: [PATCH 049/124] pgvector size increase to 30GiB --- manifests/immich/database.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifests/immich/database.yaml b/manifests/immich/database.yaml index 46c0bed..154151f 100644 --- a/manifests/immich/database.yaml +++ b/manifests/immich/database.yaml @@ -7,7 +7,7 @@ spec: imageName: "ghcr.io/tensorchord/cloudnative-pgvecto.rs:16-v0.3.0" instances: 1 storage: - size: 10Gi + size: 30Gi primaryUpdateStrategy: unsupervised postgresql: shared_preload_libraries: From f5abc62d65a729b96a7edb08f0a771988bd48296 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 28 Jul 2025 20:33:49 -0500 Subject: [PATCH 050/124] Update nixpkgs --- flake.lock | 84 +++++++++++++++++++++++++++--------------------------- 1 file changed, 42 insertions(+), 42 deletions(-) diff --git a/flake.lock b/flake.lock index cd39408..f5edfdd 100644 --- a/flake.lock +++ b/flake.lock @@ -31,11 +31,11 @@ "nixpkgs-unstable": "nixpkgs-unstable" }, "locked": { - "lastModified": 1751530600, - "narHash": "sha256-9YzlL/TIcVmuqXbN5VKEjzLAUO189h0DOBq9eNGgpaQ=", + "lastModified": 1753079037, + "narHash": "sha256-c1MvgF+0dU75CmowEAez8oC+M9dtXZ5WKfDZzuFTkP0=", "owner": "fort-nix", "repo": "nix-bitcoin", - "rev": "e2ca2e496769a787a06c068acb43cb077c1fdc8c", + "rev": "5031e254696c72f36a7e41ddf70dacdf6bd83e46", "type": "github" }, "original": { @@ -187,11 +187,11 @@ ] }, "locked": { - "lastModified": 1751413152, - "narHash": "sha256-Tyw1RjYEsp5scoigs1384gIg6e0GoBVjms4aXFfRssQ=", + "lastModified": 1753121425, + "narHash": "sha256-TVcTNvOeWWk1DXljFxVRp+E0tzG1LhrVjOGGoMHuXio=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "77826244401ea9de6e3bac47c2db46005e1f30b5", + "rev": "644e0fc48951a860279da645ba77fe4a6e814c5e", "type": "github" }, "original": { @@ -226,11 +226,11 @@ "nixpkgs-lib": "nixpkgs-lib_2" }, "locked": { - "lastModified": 1751413152, - "narHash": "sha256-Tyw1RjYEsp5scoigs1384gIg6e0GoBVjms4aXFfRssQ=", + "lastModified": 1753121425, + "narHash": "sha256-TVcTNvOeWWk1DXljFxVRp+E0tzG1LhrVjOGGoMHuXio=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "77826244401ea9de6e3bac47c2db46005e1f30b5", + "rev": "644e0fc48951a860279da645ba77fe4a6e814c5e", "type": "github" }, "original": { @@ -321,11 +321,11 @@ ] }, "locked": { - "lastModified": 1753180535, - "narHash": "sha256-KEtlzMs2O7FDvciFtjk9W4hyau013Pj9qZNK9a0PxEc=", + "lastModified": 1753732062, + "narHash": "sha256-vojVM0SgFP8crFh1LDDXkzaI9/er/1cuRfbNPhfBHyc=", "owner": "nix-community", "repo": "home-manager", - "rev": "847711c7ffa9944b0c5c39a8342ac8eb6a9f9abc", + "rev": "f49e872f55e36e67ebcb906ff65f86c7a1538f7c", "type": "github" }, "original": { @@ -457,11 +457,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1750969886, - "narHash": "sha256-zW/OFnotiz/ndPFdebpo3X0CrbVNf22n4DjN2vxlb58=", + "lastModified": 1752866191, + "narHash": "sha256-NV4S2Lf2hYmZQ3Qf4t/YyyBaJNuxLPyjzvDma0zPp/M=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "a676066377a2fe7457369dd37c31fd2263b662f4", + "rev": "f01fe91b0108a7aff99c99f2e9abbc45db0adc2a", "type": "github" }, "original": { @@ -518,11 +518,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1750994206, - "narHash": "sha256-3u6rEbIX9CN/5A5/mc3u0wIO1geZ0EhjvPBXmRDHqWM=", + "lastModified": 1752900028, + "narHash": "sha256-dPALCtmik9Wr14MGqVXm+OQcv7vhPBXcWNIOThGnB/Q=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "80d50fc87924c2a0d346372d242c27973cf8cdbf", + "rev": "6b4955211758ba47fac850c040a27f23b9b4008f", "type": "github" }, "original": { @@ -565,11 +565,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1752950548, - "narHash": "sha256-NS6BLD0lxOrnCiEOcvQCDVPXafX1/ek1dfJHX1nUIzc=", + "lastModified": 1753549186, + "narHash": "sha256-Znl7rzuxKg/Mdm6AhimcKynM7V3YeNDIcLjBuoBcmNs=", "owner": "nixos", "repo": "nixpkgs", - "rev": "c87b95e25065c028d31a94f06a62927d18763fdf", + "rev": "17f6bd177404d6d43017595c5264756764444ab8", "type": "github" }, "original": { @@ -597,11 +597,11 @@ }, "nixunstable": { "locked": { - "lastModified": 1752950548, - "narHash": "sha256-NS6BLD0lxOrnCiEOcvQCDVPXafX1/ek1dfJHX1nUIzc=", + "lastModified": 1753549186, + "narHash": "sha256-Znl7rzuxKg/Mdm6AhimcKynM7V3YeNDIcLjBuoBcmNs=", "owner": "nixos", "repo": "nixpkgs", - "rev": "c87b95e25065c028d31a94f06a62927d18763fdf", + "rev": "17f6bd177404d6d43017595c5264756764444ab8", "type": "github" }, "original": { @@ -621,11 +621,11 @@ "systems": "systems_4" }, "locked": { - "lastModified": 1752976861, - "narHash": "sha256-59HcrqHfbSJUdmpzrAa9x8fW1PoS+ZGhCjL5k5HbyV8=", + "lastModified": 1753706533, + "narHash": "sha256-ZNyVwyj+4qvaOT/gQWfNypP8qtHmXtt02D9WDZH4IPU=", "owner": "nix-community", "repo": "nixvim", - "rev": "0c50ed9349199219583cb1ed1a972d71e06039ec", + "rev": "e1aa35fb04047df11a9c1ab539a0bac35ddad509", "type": "github" }, "original": { @@ -641,11 +641,11 @@ "nixpkgs": "nixpkgs_3" }, "locked": { - "lastModified": 1753197323, - "narHash": "sha256-XqeaKquaFebKMhyl7ty+OJaB91tmXstX5BZh/gRbKag=", + "lastModified": 1753746745, + "narHash": "sha256-1Ii4RX2gUAp5KtdQOLokBMJ0dKeqabAeiS18NirGI6o=", "owner": "nix-community", "repo": "NUR", - "rev": "6a546a5059e6b803b6bca4a2f8ecbf6729630339", + "rev": "678f454f7f1b884cea5a8b266937969693419acf", "type": "github" }, "original": { @@ -664,11 +664,11 @@ ] }, "locked": { - "lastModified": 1749730855, - "narHash": "sha256-L3x2nSlFkXkM6tQPLJP3oCBMIsRifhIDPMQQdHO5xWo=", + "lastModified": 1753450833, + "narHash": "sha256-Pmpke0JtLRzgdlwDC5a+aiLVZ11JPUO5Bcqkj0nHE/k=", "owner": "NuschtOS", "repo": "search", - "rev": "8dfe5879dd009ff4742b668d9c699bc4b9761742", + "rev": "40987cc1a24feba378438d691f87c52819f7bd75", "type": "github" }, "original": { @@ -831,11 +831,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1753150460, - "narHash": "sha256-q2dkvuIfEb5fWBF6TJePJbcP1hqxARAUddfPGVGvD38=", + "lastModified": 1753669528, + "narHash": "sha256-NyDesHCYBB+VGMaTUKj6GxLeVMcpc09OI6CIxVVPVPI=", "owner": "nix-community", "repo": "nix-vscode-extensions", - "rev": "d13827556415f4050b510e9cfb9873c1ce9aaec4", + "rev": "c258332ac73118ccd664f24c2730dc66da97eb8e", "type": "github" }, "original": { @@ -852,11 +852,11 @@ ] }, "locked": { - "lastModified": 1752682362, - "narHash": "sha256-ZNIpqCG/CfhmV+TgIeyO/XbhDjSWpwWokHM44j0Mn0w=", + "lastModified": 1753704990, + "narHash": "sha256-5E14xuNWy2Un1nFR55k68hgbnD8U2x/rE5DXJtYKusw=", "owner": "nix-community", "repo": "NixOS-WSL", - "rev": "20001f9bf0aaf2b1c307e43a5eec8cf8f800fe14", + "rev": "58c814cc6d4a789191f9c12e18277107144b0c91", "type": "github" }, "original": { @@ -873,11 +873,11 @@ ] }, "locked": { - "lastModified": 1752421971, - "narHash": "sha256-bxzE0OeFcLPQSKtxTzMUBx9Y5cw4Ni3v2RIFvD38ctA=", + "lastModified": 1753710377, + "narHash": "sha256-BzLY5DaMNIgz1VMNlIVN4JmLdFk5RKDvnRmKcSm9kWw=", "owner": "HPsaucii", "repo": "zed-editor-flake", - "rev": "fa1af347db694c06e6b927a4acf3e4c455c2ae37", + "rev": "9428722af57e98fa38fd157dbf37cb173c39d09c", "type": "github" }, "original": { From d52109f7f77c69d7f48075b7b474b34c47b790a2 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 28 Jul 2025 20:34:00 -0500 Subject: [PATCH 051/124] Add mumble and kdenlive --- home/hosts/exodus/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/home/hosts/exodus/default.nix b/home/hosts/exodus/default.nix index 45d576f..2d29c75 100644 --- a/home/hosts/exodus/default.nix +++ b/home/hosts/exodus/default.nix @@ -14,9 +14,11 @@ freeciv gimp k9s + kdePackages.kdenlive kubernetes-helm kubectl kubectl-cnpg + mumble wineWowPackages.stable ]; } From a042a3a0e018cd7abceae67442ea3ebe4b114c24 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 28 Jul 2025 22:13:03 -0500 Subject: [PATCH 052/124] Fix formatting --- darwin/baseline.nix | 1 - home/baseline/tools.nix | 25 ++++++++++++++----------- modules/hm/gui.nix | 2 +- pkgs/hms/default.nix | 12 ++++++++++-- 4 files changed, 25 insertions(+), 15 deletions(-) diff --git a/darwin/baseline.nix b/darwin/baseline.nix index e6bb11e..ddb199f 100644 --- a/darwin/baseline.nix +++ b/darwin/baseline.nix @@ -1,5 +1,4 @@ { - config, pkgs, ... }: diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index e40f890..f519db9 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -1,16 +1,19 @@ { lib, pkgs, ... }: { - home.packages = with pkgs; [ - dig - dnsutils - jqp - iamb - rainfrog - tenere - wiki-tui - ] ++ (lib.optionals pkgs.stdenv.hostPlatform.isLinux [ - impala - ]); + home.packages = + with pkgs; + [ + dig + dnsutils + jqp + iamb + rainfrog + tenere + wiki-tui + ] + ++ (lib.optionals pkgs.stdenv.hostPlatform.isLinux [ + impala + ]); programs = { zellij = { diff --git a/modules/hm/gui.nix b/modules/hm/gui.nix index f2cfa14..7df5422 100644 --- a/modules/hm/gui.nix +++ b/modules/hm/gui.nix @@ -69,7 +69,7 @@ in ]); programs.firefox = { - enable = true; #(!pkgs.stdenv.hostPlatform.isDarwin); + enable = true; # (!pkgs.stdenv.hostPlatform.isDarwin); package = pkgs.firefox-bin; policies = { DisableAppUpdate = true; diff --git a/pkgs/hms/default.nix b/pkgs/hms/default.nix index ad0235a..fede34a 100644 --- a/pkgs/hms/default.nix +++ b/pkgs/hms/default.nix @@ -1,7 +1,15 @@ -{ writeShellApplication, coreutils-full, nix-output-monitor, ... }: +{ + writeShellApplication, + coreutils-full, + nix-output-monitor, + ... +}: writeShellApplication { name = "hms"; - runtimeInputs = [ coreutils-full nix-output-monitor ]; + runtimeInputs = [ + coreutils-full + nix-output-monitor + ]; text = (builtins.readFile ./hms.sh); } From 6761cb32f2cb15b78a5e1cad80eee16d3c378a5a Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 29 Jul 2025 23:13:10 -0500 Subject: [PATCH 053/124] Move big 3 to run both Runners --- hosts/isaiah/default.nix | 13 +---- hosts/jeremiah/default.nix | 19 ++----- hosts/zeke/default.nix | 3 +- hosts/zeke/virt.nix | 60 +-------------------- modules/nixos/default.nix | 1 + modules/nixos/gitlab-runner.nix | 96 +++++++++++++++++++++++++++++++++ 6 files changed, 105 insertions(+), 87 deletions(-) create mode 100644 modules/nixos/gitlab-runner.nix diff --git a/hosts/isaiah/default.nix b/hosts/isaiah/default.nix index 9b9825d..a6d4645 100644 --- a/hosts/isaiah/default.nix +++ b/hosts/isaiah/default.nix @@ -42,6 +42,7 @@ }; tailscale.enable = true; remote-builder.enable = true; + runner.enable = true; }; fileSystems = { @@ -84,16 +85,4 @@ settings.PermitRootLogin = "yes"; }; }; - - virtualisation = { - libvirtd = { - enable = true; - allowedBridges = [ - "br0" - "virbr0" - ]; - onBoot = "ignore"; # only restart VMs labeled 'autostart' - qemu.ovmf.enable = true; - }; - }; } diff --git a/hosts/jeremiah/default.nix b/hosts/jeremiah/default.nix index d4dcfeb..8094977 100644 --- a/hosts/jeremiah/default.nix +++ b/hosts/jeremiah/default.nix @@ -82,6 +82,10 @@ in }; tailscale.enable = true; remote-builder.enable = true; + runner = { + enable = true; + threads = 3; + }; }; networking = { @@ -113,21 +117,6 @@ in age.secrets.runner-reg.file = ../../secrets/gitlab/nixos-qemu-shell.age; services = { - gitlab-runner = { - enable = true; - settings.concurrent = 3; - services = { - shell = { - executor = "shell"; - limit = 7; - authenticationTokenConfigFile = config.age.secrets.runner-reg.path; - environmentVariables = { - EFI_DIR = "${pkgs.OVMF.fd}/FV/"; - STORAGE_URL = "s3.thehellings.lan:9000"; - }; - }; - }; - }; proxmox-ve = { enable = true; ipAddress = (builtins.elemAt config.networking.interfaces.br0.ipv4.addresses 0).address; diff --git a/hosts/zeke/default.nix b/hosts/zeke/default.nix index e0cddf6..f1a8908 100644 --- a/hosts/zeke/default.nix +++ b/hosts/zeke/default.nix @@ -16,13 +16,14 @@ boot.extraModulePackages = [ config.boot.kernelPackages.v4l2loopback ]; greg = { - tailscale.enable = true; kubernetes = { enable = true; vipInterface = "enp12s0"; priority = 253; }; remote-builder.enable = true; + runner.enable = true; + tailscale.enable = true; }; hardware = { diff --git a/hosts/zeke/virt.nix b/hosts/zeke/virt.nix index 8a7d448..d3408d4 100644 --- a/hosts/zeke/virt.nix +++ b/hosts/zeke/virt.nix @@ -1,15 +1,10 @@ { - config, lib, pkgs, ... }: let - environmentVariables = { - EFI_DIR = "${pkgs.OVMF.fd}/FV/"; - STORAGE_URL = "s3.thehellings.lan:9000"; - }; passthru = [ "1002:164e" # Raphael - embedded GPU "1002:1640" # Rembrandt - Audio @@ -18,41 +13,7 @@ let ]; in { - specialisation = { - vbox.configuration = { - users.extraGroups.vboxusers.members = [ "greg" ]; - - virtualisation = { - virtualbox.host = { - enable = true; - enableExtensionPack = true; - }; - }; - - services.gitlab-runner.services = lib.mkForce { - vbox = { - inherit environmentVariables; - authenticationTokenConfigFile = config.age.secrets.vbox.path; - executor = "shell"; - limit = 5; - }; - }; - - systemd.services.gitlab-runner = { - serviceConfig = { - DevicePolicy = lib.mkForce "auto"; - User = "root"; - DynamicUser = lib.mkForce false; - }; - }; - }; - }; - - age.secrets = { - qemu.file = ../../secrets/gitlab/nixos-qemu-shell.age; - vbox.file = ../../secrets/gitlab/nixos-vbox-shell.age; - }; - + greg.runner.enable = true; # These options enable sharing of the GPU with the VM boot = { # Order matters here, to prevent the AMD driver from getting to the driver before @@ -77,17 +38,6 @@ in hardware.graphics.enable = true; - services.gitlab-runner = { - enable = true; - settings.concurrent = 5; - services.qemu = { - inherit environmentVariables; - executor = "shell"; - limit = 5; - authenticationTokenConfigFile = config.age.secrets.qemu.path; - }; - }; - systemd.services = { "libvirt-nosleep@" = { description = "Prevent sleep while %i is running"; @@ -98,14 +48,6 @@ in ''; }; }; - - gitlab-runner = { - serviceConfig = { - DevicePolicy = lib.mkForce "auto"; - User = "root"; - DynamicUser = lib.mkForce false; - }; - }; }; virtualisation = { diff --git a/modules/nixos/default.nix b/modules/nixos/default.nix index d1185e0..4be84b2 100644 --- a/modules/nixos/default.nix +++ b/modules/nixos/default.nix @@ -8,6 +8,7 @@ ./ceph.nix ./container.nix ./db.nix + ./gitlab-runner.nix ./gnome.nix ./home.nix ./kde.nix diff --git a/modules/nixos/gitlab-runner.nix b/modules/nixos/gitlab-runner.nix new file mode 100644 index 0000000..c190ac1 --- /dev/null +++ b/modules/nixos/gitlab-runner.nix @@ -0,0 +1,96 @@ +{ + config, + lib, + pkgs, + ... +}: +let + cfg = config.greg.runner; + environmentVariables = { + EFI_DIR = "${pkgs.OVMF.fd}/FV/"; + STORAGE_URL = "s3.thehellings.lan:9000"; + }; +in +{ + options.greg.runner = { + enable = lib.mkEnableOption "Enable as a gitlab-runner with both libvirt and virtualbox"; + + threads = lib.mkOption { + default = 5; + type = lib.types.int; + description = "The maximum number of concurrent jobs"; + }; + }; + + config = lib.mkIf cfg.enable { + # Shared configurations + age.secrets = { + qemu.file = ../../secrets/gitlab/nixos-qemu-shell.age; + vbox.file = ../../secrets/gitlab/nixos-vbox-shell.age; + }; + + # Defaults to running libvirt support + services.gitlab-runner = { + enable = true; + settings.concurrent = cfg.threads; + services.qemu = { + inherit environmentVariables; + executor = "shell"; + limit = cfg.threads; + authenticationTokenConfigFile = config.age.secrets.qemu.path; + }; + }; + + systemd.services.gitlab-runner = { + serviceConfig = { + DevicePolicy = lib.mkForce "auto"; + User = "root"; + DynamicUser = lib.mkForce false; + }; + }; + + virtualisation = { + libvirtd = { + enable = true; + allowedBridges = [ + "br0" + "virbr0" + ]; + onBoot = "ignore"; # only restart VMs labeled 'autostart' + qemu.ovmf.enable = true; + }; + }; + # Boot into this specialisation if you want to build vbox hosts + # with this box at that time + specialisation = { + vbox.configuration = { + users.extraGroups.vboxusers.members = [ "greg" ]; + + virtualisation = { + virtualbox.host = { + enable = true; + enableExtensionPack = true; + }; + }; + + services.gitlab-runner.services = lib.mkForce { + vbox = { + inherit environmentVariables; + authenticationTokenConfigFile = config.age.secrets.vbox.path; + executor = "shell"; + limit = 5; + }; + }; + + systemd.services.gitlab-runner = { + serviceConfig = { + DevicePolicy = lib.mkForce "auto"; + User = "root"; + DynamicUser = lib.mkForce false; + }; + }; + }; + }; + + }; +} From ae1c1260d2643dc82514551e6b6bd1eca6a26a81 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 29 Jul 2025 23:13:40 -0500 Subject: [PATCH 054/124] Remove custom zeditor flake --- flake.lock | 57 +----------------------------------------------------- flake.nix | 7 ------- 2 files changed, 1 insertion(+), 63 deletions(-) diff --git a/flake.lock b/flake.lock index f5edfdd..0f70948 100644 --- a/flake.lock +++ b/flake.lock @@ -221,24 +221,6 @@ "type": "github" } }, - "flake-parts_4": { - "inputs": { - "nixpkgs-lib": "nixpkgs-lib_2" - }, - "locked": { - "lastModified": 1753121425, - "narHash": "sha256-TVcTNvOeWWk1DXljFxVRp+E0tzG1LhrVjOGGoMHuXio=", - "owner": "hercules-ci", - "repo": "flake-parts", - "rev": "644e0fc48951a860279da645ba77fe4a6e814c5e", - "type": "github" - }, - "original": { - "owner": "hercules-ci", - "repo": "flake-parts", - "type": "github" - } - }, "flake-utils": { "inputs": { "systems": "systems_2" @@ -486,21 +468,6 @@ "type": "github" } }, - "nixpkgs-lib_2": { - "locked": { - "lastModified": 1751159883, - "narHash": "sha256-urW/Ylk9FIfvXfliA1ywh75yszAbiTEVgpPeinFyVZo=", - "owner": "nix-community", - "repo": "nixpkgs.lib", - "rev": "14a40a1d7fb9afa4739275ac642ed7301a9ba1ab", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "nixpkgs.lib", - "type": "github" - } - }, "nixpkgs-stable": { "locked": { "lastModified": 1748437600, @@ -713,8 +680,7 @@ "nurpkgs": "nurpkgs", "proxmox": "proxmox", "vsext": "vsext", - "wsl": "wsl", - "zed": "zed" + "wsl": "wsl" } }, "systems": { @@ -864,27 +830,6 @@ "repo": "NixOS-WSL", "type": "github" } - }, - "zed": { - "inputs": { - "flake-parts": "flake-parts_4", - "nixpkgs": [ - "nixunstable" - ] - }, - "locked": { - "lastModified": 1753710377, - "narHash": "sha256-BzLY5DaMNIgz1VMNlIVN4JmLdFk5RKDvnRmKcSm9kWw=", - "owner": "HPsaucii", - "repo": "zed-editor-flake", - "rev": "9428722af57e98fa38fd157dbf37cb173c39d09c", - "type": "github" - }, - "original": { - "owner": "HPsaucii", - "repo": "zed-editor-flake", - "type": "github" - } } }, "root": "root", diff --git a/flake.nix b/flake.nix index cd6ca1b..0ee2160 100644 --- a/flake.nix +++ b/flake.nix @@ -50,10 +50,6 @@ url = "github:nix-community/NixOS-WSL"; inputs.nixpkgs.follows = "nixunstable"; }; - zed = { - url = "github:HPsaucii/zed-editor-flake"; - inputs.nixpkgs.follows = "nixunstable"; - }; }; outputs = @@ -66,9 +62,6 @@ inherit self top; pkgs = prev; }) - // { - zed-editor = top.zed.packages."${prev.stdenv.hostPlatform.system}".zed-editor; - } ); overlays = [ top.agenix.overlays.default From 47f2653d439e2adf855435b73396b9915fc73f28 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 1 Aug 2025 10:24:15 -0500 Subject: [PATCH 055/124] Add ghostty and settings --- darwin/hosts/ivr/default.nix | 5 +++++ home/baseline/default.nix | 1 + home/baseline/shell.nix | 33 +++++++++++++++++++++++++++++++++ 3 files changed, 39 insertions(+) create mode 100644 home/baseline/shell.nix diff --git a/darwin/hosts/ivr/default.nix b/darwin/hosts/ivr/default.nix index 79cebfa..85c5c1a 100644 --- a/darwin/hosts/ivr/default.nix +++ b/darwin/hosts/ivr/default.nix @@ -21,6 +21,10 @@ in "poetry" "podman" "podman-compose" + { + name = "postgresql@17"; + restart_service = true; + } "pytest" "qemu" ]; @@ -31,6 +35,7 @@ in "bruno" "chromium" "dbeaver-community" + "ghostty" "firefox" "microsoft-teams" "onlyoffice" diff --git a/home/baseline/default.nix b/home/baseline/default.nix index 9c3876c..066f45d 100644 --- a/home/baseline/default.nix +++ b/home/baseline/default.nix @@ -7,6 +7,7 @@ ./direnv.nix ./git.nix ./nushell.nix + ./shell.nix ./ssh.nix ./tools.nix ./vim diff --git a/home/baseline/shell.nix b/home/baseline/shell.nix new file mode 100644 index 0000000..ee51861 --- /dev/null +++ b/home/baseline/shell.nix @@ -0,0 +1,33 @@ +{ pkgs, ... }: +{ + programs = { + ghostty = { + enable = true; + package = if pkgs.stdenv.hostPlatform.isDarwin then pkgs.ghostty-bin else pkgs.ghostty; + settings = { + font-family = "Hacker"; + theme = "Dracula"; + scrollback-limit = "1000000"; + window-save-state = "always"; + + keybind = [ + "ctrl+n=new_window" + + "ctrl+h=goto_split:left" + "ctrl+j=goto_split:down" + "ctrl+k=goto_split:up" + "ctrl+l=goto_split:right" + + "ctrl+b>h=new_split:left" + "ctrl+b>j=new_split:down" + "ctrl+b>k=new_split:up" + "ctrl+b>l=new_split:right" + + "ctrl+b>t=new_tab" + "ctrl+b>n=next_tab" + "ctrl+b>p=previous_tab" + ]; + }; + }; + }; +} From 1c05bfc03615c460f14ae37b7625019b20b203a8 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 1 Aug 2025 10:25:13 -0500 Subject: [PATCH 056/124] Adjust work commands --- darwin/hosts/ivr/default.nix | 9 +++++++-- home/hosts/ivr/default.nix | 1 + 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/darwin/hosts/ivr/default.nix b/darwin/hosts/ivr/default.nix index 85c5c1a..230ca6b 100644 --- a/darwin/hosts/ivr/default.nix +++ b/darwin/hosts/ivr/default.nix @@ -11,7 +11,12 @@ in enable = true; brews = [ "bitwarden-cli" + { + name = "colima"; + restart_service = true; + } "direnv" + "docker-compose" { name = "libvirt"; restart_service = true; @@ -19,8 +24,6 @@ in "mysql" "nushell" "poetry" - "podman" - "podman-compose" { name = "postgresql@17"; restart_service = true; @@ -35,9 +38,11 @@ in "bruno" "chromium" "dbeaver-community" + "docker" "ghostty" "firefox" "microsoft-teams" + "mysqlworkbench" "onlyoffice" "pgadmin4" "podman-desktop" diff --git a/home/hosts/ivr/default.nix b/home/hosts/ivr/default.nix index 0e0354e..41d76e1 100644 --- a/home/hosts/ivr/default.nix +++ b/home/hosts/ivr/default.nix @@ -33,6 +33,7 @@ in ansible direnv home-manager + just k9s kubectl minikube From 905664b7de73d62d9c070f4b7dbe18c979dcac07 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 7 Aug 2025 11:24:37 -0500 Subject: [PATCH 057/124] Zellij default shell Xonsh --- home/baseline/tools.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index f519db9..4f1af94 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -21,6 +21,7 @@ attachExistingSession = true; enableZshIntegration = pkgs.stdenv.hostPlatform.isDarwin; settings = { + default_shell = "xonsh"; keybinds = { normal._children = [ { From 3785ed6933df2e9212e449a894c93bc0b874ddff Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 11 Aug 2025 14:04:51 -0500 Subject: [PATCH 058/124] More updates for Zellij --- home/baseline/tools.nix | 85 ++++++++++++++++++++++++++++++++++-- home/baseline/vim/config.nix | 1 + 2 files changed, 83 insertions(+), 3 deletions(-) diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index 4f1af94..a89614b 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -22,19 +22,98 @@ enableZshIntegration = pkgs.stdenv.hostPlatform.isDarwin; settings = { default_shell = "xonsh"; + plugins = { + autolock = { + _props.location = "https://github.com/fresh2dev/zellij-autolock/releases/download/0.2.2/zellij-autolock.wasm"; + _children = [ { + is_enabled = true; + } { + triggers = "nvim|vim|git"; + } { + reaction_seconds = "0.3"; + } { + print_to_log = true; + } ]; + }; + }; + load_plugins.autolock = {}; keybinds = { normal._children = [ { bind = { - _args = [ "Ctrl b" ]; + _args = [ "Enter" ]; + _children = [ { + WriteChars = "\\u{000D}"; + MessagePlugin = { + _args = [ "autolock" ]; + _children = [{}]; + }; + } ]; + }; + } + { + bind = { + _args = [ "Ctrl z" ]; _children = [ { - SwitchToMode._args = [ "locked" ]; + MessagePlugin = { + _args = [ "autolock" ]; + _children = [ + { + payload._args = [ "enable" ]; + } + ]; + }; + SwitchToMode._args = [ "Locked" ]; } ]; }; } - ]; + ]; # /normal + locked._children = [ + { + bind = { + _args = [ "Ctrl z" ]; + _children = [ + { + MessagePlugin = { + _args = [ "autolock" ]; + _children = [ + { + payload._args = [ "disable" ]; + } + ]; + }; + SwitchToMode._args = [ "Normal" ]; + } + ]; + }; + } + ]; # /locked + shared_except = { + _args = [ "locked" ]; + _children = [ { + bind = { + _args = [ "Ctrl h" ]; + MoveFocusOrTab._args = [ "Left" ]; + }; + } { + bind = { + _args = [ "Ctrl j" ]; + MoveFocus._args = [ "Down" ]; + }; + } { + bind = { + _args = [ "Ctrl k" ]; + MoveFocus._args = [ "Up" ]; + }; + } { + bind = { + _args = [ "Ctrl l" ]; + MoveFocusOrTab._args = [ "Right" ]; + }; + } ]; + }; # /shared_except }; # /keybinds }; # /settings }; diff --git a/home/baseline/vim/config.nix b/home/baseline/vim/config.nix index 6512b74..69f0998 100644 --- a/home/baseline/vim/config.nix +++ b/home/baseline/vim/config.nix @@ -135,6 +135,7 @@ notify.enable = true; remote-nvim.enable = true; web-devicons.enable = true; + zellij.enable = true; }; userCommands = { Ggr = { From c691b6b8a16a72659dc7296741f92c6893a9fa06 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 13 Aug 2025 13:39:34 -0500 Subject: [PATCH 059/124] Fix Ghostty settings --- home/baseline/shell.nix | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/home/baseline/shell.nix b/home/baseline/shell.nix index ee51861..cf5c63d 100644 --- a/home/baseline/shell.nix +++ b/home/baseline/shell.nix @@ -5,6 +5,7 @@ enable = true; package = if pkgs.stdenv.hostPlatform.isDarwin then pkgs.ghostty-bin else pkgs.ghostty; settings = { + command = "~/.nix-profile/bin/xonsh"; font-family = "Hacker"; theme = "Dracula"; scrollback-limit = "1000000"; @@ -13,10 +14,10 @@ keybind = [ "ctrl+n=new_window" - "ctrl+h=goto_split:left" - "ctrl+j=goto_split:down" - "ctrl+k=goto_split:up" - "ctrl+l=goto_split:right" + "ctrl+shift+h=goto_split:left" + "ctrl+shift+j=goto_split:down" + "ctrl+shift+k=goto_split:up" + "ctrl+shift+l=goto_split:right" "ctrl+b>h=new_split:left" "ctrl+b>j=new_split:down" From a1be0912da0c7285e778db60e35bb92548adf437 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 13 Aug 2025 22:32:54 -0500 Subject: [PATCH 060/124] Standardize lots of shell aliases --- home/baseline/bash.nix | 21 ++++---------- home/baseline/nushell.nix | 22 +-------------- home/baseline/shell.nix | 58 +++++++++++++++++++++++++++++++++++++-- home/baseline/xonsh.nix | 36 ------------------------ 4 files changed, 62 insertions(+), 75 deletions(-) diff --git a/home/baseline/bash.nix b/home/baseline/bash.nix index a8b6747..ff5a32e 100644 --- a/home/baseline/bash.nix +++ b/home/baseline/bash.nix @@ -1,26 +1,15 @@ -{ pkgs, ... }: +{ config, pkgs, ... }: { programs.bash = { enable = true; shellAliases = { - acp = "rsync --progress -ah"; - agbuild = "ansible-galaxy collection build"; - apub = "ansible-galaxy collection publish --api-key \${GALAXY_API_KEY}"; + gh-personal = "$GH_CONFIG_DIR=\"${config.home.homeDirectory}/.config/gh/personal\" gh"; + ls = "ls --color"; + ll = "ls -l --color"; + calc = "bc"; d = "deactivate"; - devroles = "cd ~/src/ansible_collections/devroles"; - gohome = "ssh greg@dns.greg-hellings.gmail.com.beta.tailscale.net -D localhost:10080"; - ll = "ls -l"; - molcol = "molecule -c ../../tests/molecule.yml"; - packaging = "cd ~/src/packaging"; - vdown = "vagrant destroy"; - vhalt = "vagrant halt"; - vos = "vagrant up --provision --provider openstack"; - vprov = "vagrant provision"; - vssh = "vagrant ssh"; - vup = "vagrant up --provision --provider libvirt"; - yaml2js = "python -c 'import sys, yaml, json; json.dump(yaml.load(sys.stdin), sys.stdout, indent=4)"; }; sessionVariables = { ANSIBLE_COLLECTIONS_PATH = "\${HOME}/src/"; diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index 4c65708..0cbd4a7 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -5,25 +5,8 @@ }: { programs = { - carapace = { - enable = true; - enableNushellIntegration = true; - }; - direnv = { - enable = true; - enableNushellIntegration = true; - }; nushell = { enable = true; - environmentVariables = { - AWS_SHARED_CREDENTIALS_FILE = "/run/agenix/cache-credentials"; - GOPATH = "${config.home.homeDirectory}/src/go"; - GOBIN = "${config.home.homeDirectory}/src/bin"; - LIBMYSQL_ENABLE_CLEARTEXT_PLUGIN = "1"; - SWORD_PATH = "${config.home.homeDirectory}/.sword/"; - #TIMEFORMAT = "%3Uu %3Ss %3lR %P%%"; - VIRTUALENV_HOME = "${config.home.homeDirectory}/venv/"; - }; extraConfig = '' use std/util "path add" path add ${config.home.homeDirectory}/src/bin @@ -35,9 +18,6 @@ buffer_editor = lib.getExe config.programs.nixvim.package; }; }; - starship = { - enable = true; - enableNushellIntegration = true; - }; }; + home.shell.enableNushellIntegration = true; } diff --git a/home/baseline/shell.nix b/home/baseline/shell.nix index cf5c63d..201c7f7 100644 --- a/home/baseline/shell.nix +++ b/home/baseline/shell.nix @@ -1,11 +1,62 @@ -{ pkgs, ... }: +{ config, pkgs, ... }: { + home = { + sessionVariables = { + AWS_SHARED_CREDENTIALS_FILE = "/run/agenix/cache-credentials"; + CARAPACE_BRIDGES = "zsh,bash"; + EDITOR = "nvim"; + GOPATH = "${config.home.homeDirectory}/src/go"; + GOBIN = "${config.home.homeDirectory}/src/bin"; + LIBMYSQL_ENABLE_CLEARTEXT_PLUGIN = "1"; + MAVEN_OPTS = " -Dmaven.wagon.http.ssl.insecure=true"; + SWORD_PATH = "${config.home.homeDirectory}/.sword/"; + #TIMEFORMAT = "%3Uu %3Ss %3lR %P%%"; + VIRTUALENV_HOME = "${config.home.homeDirectory}/venv/"; + }; + shellAliases = { + nb = "nix build -L"; + nixdu = "sudo nix-store --gc --print-roots | egrep -v \"^(/nix/var|/run/\\\\w+-system|\\\\{memory|/proc)\""; + nixtest = "nixpkgs-review rev HEAD"; + nixup = "nix flake lock update"; + nixcopy = "nix copy --to \"s3://binary-cache/?profile=default&endpoint=nas.home%3A9000&scheme=http\""; + s = "nix run \".#runserver\""; + updateScript = "nix-shell maintainers/scripts/update.nix --argstr package"; + + # General + k = "kubectl"; + kn = "kubectl get nodes -o wide"; + kp = "kubectl get pods -o wide"; + win = "sudo virsh start win10"; + yaml2js = "python -c 'import sys, yaml, json; json.dump(yaml.load(sys.stdin), sys.stdout, indent=4)"; + z = "zeditor ."; + + # Tailscale related ones + tsup = "sudo tailscale up"; + tspub = "sudo tailscale up --exit-node=linode"; + tshome = "sudo tailscale up --exit-node=2maccabees"; + tsclear = "sudo tailscale up --exit-node=''"; + + # Vagrant related + vdown = "vagrant destroy"; + vhalt = "vagrant halt"; + vos = "vagrant up --provision --provider openstack"; + vprov = "vagrant provision"; + vup = "vagrant up --provision --provider libvirt"; + vssh = "vagrant ssh"; + }; + }; programs = { + carapace = { + enable = true; + }; + direnv = { + enable = true; + }; ghostty = { enable = true; package = if pkgs.stdenv.hostPlatform.isDarwin then pkgs.ghostty-bin else pkgs.ghostty; settings = { - command = "~/.nix-profile/bin/xonsh"; + command = if pkgs.stdenv.hostPlatform.isDarwin then "~/.nix-profile/bin/xonsh" else "nu"; font-family = "Hacker"; theme = "Dracula"; scrollback-limit = "1000000"; @@ -30,5 +81,8 @@ ]; }; }; + starship = { + enable = true; + }; }; } diff --git a/home/baseline/xonsh.nix b/home/baseline/xonsh.nix index 5893947..846ac4a 100644 --- a/home/baseline/xonsh.nix +++ b/home/baseline/xonsh.nix @@ -20,11 +20,9 @@ sessionVariables = { # This is for pushing builds to my local S3 cache - AWS_SHARED_CREDENTIALS_FILE = "/run/agenix/cache-credentials"; CARAPACE_BRIDGES = "zsh,bash"; COMPLETIONS_CONFIRM = "True"; CLICOLOR = 1; - EDITOR = "nvim"; # vte_new_tab_cwd causes new Terminal tabs to open in the # same CWD as the current tab LESS_TERMCAP_mb = "\\033[01;31m"; # begin blinking @@ -36,10 +34,8 @@ LESS_TERMCAP_ue = "\\033[0m"; # end underline LIBMYSQL_ENABLE_CLEARTEXT_PLUGIN = "1"; LSCOLORS = "ExGxBxDxCxEgEdxbxgxcxd"; - MAVEN_OPTS = " -Dmaven.wagon.http.ssl.insecure=true"; OS_CLOUD = "default"; PROMPT = "{vte_new_tab_cwd}{env_name}{BOLD_GREEN}{user}@{hostname}{BOLD_BLUE} {short_cwd}{branch_color}{curr_branch: {}}{RESET} {BOLD_BLUE}{prompt_end}{RESET} "; - SWORD_PATH = "${config.home.homeDirectory}/.sword/"; #TIMEFORMAT = "%3Uu %3Ss %3lR %P%%"; # Tells vox where to find virtualenvs VIRTUALENV_HOME = "${config.home.homeDirectory}/venv/"; @@ -53,42 +49,10 @@ # Python related ones ac = "vox activate"; d = "vox deactivate"; - s = "nix run \".#runserver\""; - # Nix related ones - gl-nging = "sudo nixos-container run gitlab -- systemctl restart nginx"; - nb = "nix build -L"; - nixdu = "sudo nix-store --gc --print-roots | egrep -v r\"^(/nix/var|/run/\\w+-system|\\{memory|/proc)\""; - nixtest = "nixpkgs-review rev HEAD"; - nixup = "nix flake lock --update-input"; - nixcopy = "nix copy --to \"s3://binary-cache/?profile=default&endpoint=nas.home%3A9000&scheme=http\""; - stable = "nix flake lock --update-input nixstable --update-input hm --update-input nixvimstable"; - unstable = "nix flake lock --update-input nixunstable --update-input hmunstable --update-input nixvimunstable --update-input nurpkgs --update-input vsext --update-input wsl"; - updateScript = "nix-shell maintainers/scripts/update.nix --argstr package"; - - # General gh-personal = "$GH_CONFIG_DIR=\"${config.home.homeDirectory}/.config/gh/personal\" gh"; - k = "kubectl"; - kn = "kubectl get nodes -o wide"; - kp = "kubectl get pods -o wide"; ls = "ls --color"; ll = "ls -l --color"; - win = "sudo virsh start win10"; - z = "zeditor ."; - - # Tailscale related ones - tsup = "sudo tailscale up"; - tspub = "sudo tailscale up --exit-node=linode"; - tshome = "sudo tailscale up --exit-node=2maccabees"; - tsclear = "sudo tailscale up --exit-node=''"; - - # Vagrant related - vdown = "vagrant destroy"; - vhalt = "vagrant halt"; - vos = "vagrant up --provision --provider openstack"; - vprov = "vagrant provision"; - vup = "vagrant up --provision --provider libvirt"; - vssh = "vagrant ssh"; }; configHeader = builtins.readFile ./xonsh_header.xsh; From 6abd6e9781380c9a49b85d100d4c061f7cab5cc2 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 13 Aug 2025 22:39:12 -0500 Subject: [PATCH 061/124] Fix yaml2js --- home/baseline/shell.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/home/baseline/shell.nix b/home/baseline/shell.nix index 201c7f7..02b09f1 100644 --- a/home/baseline/shell.nix +++ b/home/baseline/shell.nix @@ -27,7 +27,7 @@ kn = "kubectl get nodes -o wide"; kp = "kubectl get pods -o wide"; win = "sudo virsh start win10"; - yaml2js = "python -c 'import sys, yaml, json; json.dump(yaml.load(sys.stdin), sys.stdout, indent=4)"; + yaml2js = "python -c 'import sys, yaml, json; json.dump(yaml.load(sys.stdin), sys.stdout, indent=4)'"; z = "zeditor ."; # Tailscale related ones From 218cc3f7cc66d4eacc81279238be27129c93fb1b Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 15 Aug 2025 13:34:02 -0500 Subject: [PATCH 062/124] Improved macOS Nushell tweaks --- home/baseline/nushell.nix | 1 + home/baseline/shell.nix | 8 ++++++-- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index 0cbd4a7..583cf7a 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -16,6 +16,7 @@ ''; settings = { buffer_editor = lib.getExe config.programs.nixvim.package; + "history.isolation" = true; }; }; }; diff --git a/home/baseline/shell.nix b/home/baseline/shell.nix index 02b09f1..e53d7a4 100644 --- a/home/baseline/shell.nix +++ b/home/baseline/shell.nix @@ -1,6 +1,10 @@ -{ config, pkgs, ... }: +{ config, lib, pkgs, ... }: { home = { + file = lib.mkIf pkgs.hostPlatform.isDarwin { + #"Library/Application Support/com.mitchellh.ghostty/config".source = "${config.home.homeDirectory}/.config/ghostty/config"; + "Library/Application Support/com.mitchellh.ghostty/config".source = config.xdg.configFile."ghostty/config".source; + }; sessionVariables = { AWS_SHARED_CREDENTIALS_FILE = "/run/agenix/cache-credentials"; CARAPACE_BRIDGES = "zsh,bash"; @@ -56,7 +60,7 @@ enable = true; package = if pkgs.stdenv.hostPlatform.isDarwin then pkgs.ghostty-bin else pkgs.ghostty; settings = { - command = if pkgs.stdenv.hostPlatform.isDarwin then "~/.nix-profile/bin/xonsh" else "nu"; + command = lib.getExe pkgs.nushell; font-family = "Hacker"; theme = "Dracula"; scrollback-limit = "1000000"; From 5d883cdcfc270b3cf9bbec551409a893bfb9fbdd Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 15 Aug 2025 21:29:43 -0500 Subject: [PATCH 063/124] Move things into more hierarchical namespaces --- manifests/apply.sh | 5 +- manifests/bitwarden/kustomization.yaml | 1 + .../namespace.yaml} | 0 manifests/databases/kustomization.yaml | 2 + .../db.yaml => databases/namespace.yaml} | 0 manifests/databases/secrets.yaml | 135 ++++++++++++++++++ manifests/gitlab-runner/kustomization.yaml | 2 + .../namespace.yaml} | 0 .../secrets.yaml} | 0 manifests/kustomization.yaml | 2 - manifests/matrix/kustomization.yaml | 1 + .../matrix.yaml => matrix/namespace.yaml} | 0 manifests/namespaces/kustomization.yaml | 5 - manifests/secrets/k3sbackup.yaml | 33 ----- manifests/secrets/kustomization.yaml | 5 - manifests/secrets/postgres-user-gitlab.yaml | 33 ----- manifests/secrets/postgres-user-matrix.yaml | 33 ----- manifests/secrets/postgres-user-pgadmin.yaml | 33 ----- 18 files changed, 143 insertions(+), 147 deletions(-) rename manifests/{namespaces/bitwarden.yaml => bitwarden/namespace.yaml} (100%) rename manifests/{namespaces/db.yaml => databases/namespace.yaml} (100%) create mode 100644 manifests/databases/secrets.yaml rename manifests/{namespaces/gitlab-runner.yaml => gitlab-runner/namespace.yaml} (100%) rename manifests/{secrets/gitlab-runner.yaml => gitlab-runner/secrets.yaml} (100%) rename manifests/{namespaces/matrix.yaml => matrix/namespace.yaml} (100%) delete mode 100644 manifests/namespaces/kustomization.yaml delete mode 100644 manifests/secrets/k3sbackup.yaml delete mode 100644 manifests/secrets/postgres-user-gitlab.yaml delete mode 100644 manifests/secrets/postgres-user-matrix.yaml delete mode 100644 manifests/secrets/postgres-user-pgadmin.yaml diff --git a/manifests/apply.sh b/manifests/apply.sh index 21f056a..0907a9d 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -21,15 +21,12 @@ kubectl annotate nodes --overwrite zeke 'node.longhorn.io/default-disks-config=[ { "path": "/var/lib/longhorn", "allowScheduling" : trues, "tags": ["ssd", "fast"]} ]' -kubectl apply -k namespaces kubectl apply -f helm/flux.yaml sleep 5 kubectl apply -f helm/kyverno.yaml sleep 15 kubectl apply -k helm sleep 5 -kubectl apply -k . -sleep 5 # https://cloudnative-pg.io helm repo add cnpg https://cloudnative-pg.github.io/charts/ helm upgrade --install cnpg \ @@ -37,5 +34,7 @@ helm upgrade --install cnpg \ cnpg/cloudnative-pg \ -f values/cnpg.yaml \ --wait +sleep 5 +kubectl apply -k . ./immich/apply.sh diff --git a/manifests/bitwarden/kustomization.yaml b/manifests/bitwarden/kustomization.yaml index 6154c52..65ded28 100644 --- a/manifests/bitwarden/kustomization.yaml +++ b/manifests/bitwarden/kustomization.yaml @@ -1,6 +1,7 @@ namespace: bitwarden resources: + - namespace.yaml - deployment.yaml - service.yaml - cluster-stores.yaml diff --git a/manifests/namespaces/bitwarden.yaml b/manifests/bitwarden/namespace.yaml similarity index 100% rename from manifests/namespaces/bitwarden.yaml rename to manifests/bitwarden/namespace.yaml diff --git a/manifests/databases/kustomization.yaml b/manifests/databases/kustomization.yaml index d8e8a11..3d46a2d 100644 --- a/manifests/databases/kustomization.yaml +++ b/manifests/databases/kustomization.yaml @@ -1,6 +1,8 @@ namespace: db resources: + - namespace.yaml + - secrets.yaml - postgres-cluster.yaml - postgres-gitlab.yaml - postgres-pgadmin.yaml diff --git a/manifests/namespaces/db.yaml b/manifests/databases/namespace.yaml similarity index 100% rename from manifests/namespaces/db.yaml rename to manifests/databases/namespace.yaml diff --git a/manifests/databases/secrets.yaml b/manifests/databases/secrets.yaml new file mode 100644 index 0000000..bca61d8 --- /dev/null +++ b/manifests/databases/secrets.yaml @@ -0,0 +1,135 @@ +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: postgres-user-gitlab + namespace: db +spec: + target: + name: postgres-user-gitlab + deletionPolicy: Delete + template: + type: Opaque + data: + username: |- + {{ .username }} + password: |- + {{ .password }} + data: + - secretKey: username + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57 + property: username + - secretKey: password + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57 + property: password +--- +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: postgres-user-matrix + namespace: db +spec: + target: + name: postgres-user-matrix + deletionPolicy: Delete + template: + type: Opaque + data: + username: |- + {{ .username }} + password: |- + {{ .password }} + data: + - secretKey: username + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 36d1046b-727e-4e09-a391-b2e90171d3d0 + property: username + - secretKey: password + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 36d1046b-727e-4e09-a391-b2e90171d3d0 + property: password +--- +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: postgres-user-pgadmin + namespace: db +spec: + target: + name: postgres-user-pgadmin + deletionPolicy: Delete + template: + type: Opaque + data: + username: |- + {{ .username }} + password: |- + {{ .password }} + data: + - secretKey: username + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: f333d637-1667-499d-b9a0-b2e9012bd8b7 + property: username + - secretKey: password + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: f333d637-1667-499d-b9a0-b2e9012bd8b7 + property: password +--- +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: k3sbackup + namespace: db +spec: + target: + name: k3sbackup + deletionPolicy: Delete + template: + type: Opaque + data: + username: |- + {{ .username }} + password: |- + {{ .password }} + data: + - secretKey: username + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 685b29c6-9264-4e60-ba4a-b2ea005a5d7b + property: username + - secretKey: password + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: 685b29c6-9264-4e60-ba4a-b2ea005a5d7b + property: password diff --git a/manifests/gitlab-runner/kustomization.yaml b/manifests/gitlab-runner/kustomization.yaml index ce305c5..195cdcd 100644 --- a/manifests/gitlab-runner/kustomization.yaml +++ b/manifests/gitlab-runner/kustomization.yaml @@ -1,4 +1,6 @@ namespace: gitlab-runner resources: + - namespace.yaml + - secrets.yaml - chart.yaml diff --git a/manifests/namespaces/gitlab-runner.yaml b/manifests/gitlab-runner/namespace.yaml similarity index 100% rename from manifests/namespaces/gitlab-runner.yaml rename to manifests/gitlab-runner/namespace.yaml diff --git a/manifests/secrets/gitlab-runner.yaml b/manifests/gitlab-runner/secrets.yaml similarity index 100% rename from manifests/secrets/gitlab-runner.yaml rename to manifests/gitlab-runner/secrets.yaml diff --git a/manifests/kustomization.yaml b/manifests/kustomization.yaml index 7f1876f..292400e 100644 --- a/manifests/kustomization.yaml +++ b/manifests/kustomization.yaml @@ -1,6 +1,4 @@ resources: - - namespaces - - pvc - helm - bitwarden - secrets diff --git a/manifests/matrix/kustomization.yaml b/manifests/matrix/kustomization.yaml index 34b5e68..9b7efa2 100644 --- a/manifests/matrix/kustomization.yaml +++ b/manifests/matrix/kustomization.yaml @@ -1,6 +1,7 @@ namespace: matrix resources: + - namespace.yaml - dendrite-config.yaml - deployment.yaml - service.yaml diff --git a/manifests/namespaces/matrix.yaml b/manifests/matrix/namespace.yaml similarity index 100% rename from manifests/namespaces/matrix.yaml rename to manifests/matrix/namespace.yaml diff --git a/manifests/namespaces/kustomization.yaml b/manifests/namespaces/kustomization.yaml deleted file mode 100644 index 310d54c..0000000 --- a/manifests/namespaces/kustomization.yaml +++ /dev/null @@ -1,5 +0,0 @@ -resources: - - bitwarden.yaml - - db.yaml - - gitlab-runner.yaml - - matrix.yaml diff --git a/manifests/secrets/k3sbackup.yaml b/manifests/secrets/k3sbackup.yaml deleted file mode 100644 index ec52d84..0000000 --- a/manifests/secrets/k3sbackup.yaml +++ /dev/null @@ -1,33 +0,0 @@ -apiVersion: external-secrets.io/v1 -kind: ExternalSecret -metadata: - name: k3sbackup - namespace: db -spec: - target: - name: k3sbackup - deletionPolicy: Delete - template: - type: Opaque - data: - username: |- - {{ .username }} - password: |- - {{ .password }} - data: - - secretKey: username - sourceRef: - storeRef: - name: bitwarden-login - kind: ClusterSecretStore - remoteRef: - key: 685b29c6-9264-4e60-ba4a-b2ea005a5d7b - property: username - - secretKey: password - sourceRef: - storeRef: - name: bitwarden-login - kind: ClusterSecretStore - remoteRef: - key: 685b29c6-9264-4e60-ba4a-b2ea005a5d7b - property: password diff --git a/manifests/secrets/kustomization.yaml b/manifests/secrets/kustomization.yaml index ba8494d..e378b89 100644 --- a/manifests/secrets/kustomization.yaml +++ b/manifests/secrets/kustomization.yaml @@ -1,7 +1,2 @@ resources: - - postgres-user-gitlab.yaml - - postgres-user-pgadmin.yaml - - postgres-user-matrix.yaml - - k3sbackup.yaml - - gitlab-runner.yaml - longhorn.yaml diff --git a/manifests/secrets/postgres-user-gitlab.yaml b/manifests/secrets/postgres-user-gitlab.yaml deleted file mode 100644 index fde4202..0000000 --- a/manifests/secrets/postgres-user-gitlab.yaml +++ /dev/null @@ -1,33 +0,0 @@ -apiVersion: external-secrets.io/v1 -kind: ExternalSecret -metadata: - name: postgres-user-gitlab - namespace: db -spec: - target: - name: postgres-user-gitlab - deletionPolicy: Delete - template: - type: Opaque - data: - username: |- - {{ .username }} - password: |- - {{ .password }} - data: - - secretKey: username - sourceRef: - storeRef: - name: bitwarden-login - kind: ClusterSecretStore - remoteRef: - key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57 - property: username - - secretKey: password - sourceRef: - storeRef: - name: bitwarden-login - kind: ClusterSecretStore - remoteRef: - key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57 - property: password diff --git a/manifests/secrets/postgres-user-matrix.yaml b/manifests/secrets/postgres-user-matrix.yaml deleted file mode 100644 index dff00b2..0000000 --- a/manifests/secrets/postgres-user-matrix.yaml +++ /dev/null @@ -1,33 +0,0 @@ -apiVersion: external-secrets.io/v1 -kind: ExternalSecret -metadata: - name: postgres-user-matrix - namespace: db -spec: - target: - name: postgres-user-matrix - deletionPolicy: Delete - template: - type: Opaque - data: - username: |- - {{ .username }} - password: |- - {{ .password }} - data: - - secretKey: username - sourceRef: - storeRef: - name: bitwarden-login - kind: ClusterSecretStore - remoteRef: - key: 36d1046b-727e-4e09-a391-b2e90171d3d0 - property: username - - secretKey: password - sourceRef: - storeRef: - name: bitwarden-login - kind: ClusterSecretStore - remoteRef: - key: 36d1046b-727e-4e09-a391-b2e90171d3d0 - property: password diff --git a/manifests/secrets/postgres-user-pgadmin.yaml b/manifests/secrets/postgres-user-pgadmin.yaml deleted file mode 100644 index 0f2500a..0000000 --- a/manifests/secrets/postgres-user-pgadmin.yaml +++ /dev/null @@ -1,33 +0,0 @@ -apiVersion: external-secrets.io/v1 -kind: ExternalSecret -metadata: - name: postgres-user-pgadmin - namespace: db -spec: - target: - name: postgres-user-pgadmin - deletionPolicy: Delete - template: - type: Opaque - data: - username: |- - {{ .username }} - password: |- - {{ .password }} - data: - - secretKey: username - sourceRef: - storeRef: - name: bitwarden-login - kind: ClusterSecretStore - remoteRef: - key: f333d637-1667-499d-b9a0-b2e9012bd8b7 - property: username - - secretKey: password - sourceRef: - storeRef: - name: bitwarden-login - kind: ClusterSecretStore - remoteRef: - key: f333d637-1667-499d-b9a0-b2e9012bd8b7 - property: password From 2654a8972dc735e039f7dc26e09bdc1f85d3402a Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 15 Aug 2025 22:39:00 -0500 Subject: [PATCH 064/124] Tailscale in Kubernetes Set tailscale operator up in Kubernetes Configure external services --- manifests/apply.sh | 1 + manifests/databases/postgres-pgadmin.yaml | 22 ++++++++---------- manifests/helm/longhorn.yaml | 16 +++++++++++++ manifests/immich/ingress.yaml | 18 +++++++++++++-- manifests/matrix/ingress.yaml | 28 +++++++++-------------- manifests/tailscale/apply.sh | 15 ++++++++++++ modules/hm/gui/bookmarks.nix | 10 ++++---- 7 files changed, 73 insertions(+), 37 deletions(-) create mode 100755 manifests/tailscale/apply.sh diff --git a/manifests/apply.sh b/manifests/apply.sh index 0907a9d..b9dea74 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -35,6 +35,7 @@ helm upgrade --install cnpg \ -f values/cnpg.yaml \ --wait sleep 5 +./tailscale/apply.sh kubectl apply -k . ./immich/apply.sh diff --git a/manifests/databases/postgres-pgadmin.yaml b/manifests/databases/postgres-pgadmin.yaml index 0a4ce1f..220fbf1 100644 --- a/manifests/databases/postgres-pgadmin.yaml +++ b/manifests/databases/postgres-pgadmin.yaml @@ -91,17 +91,13 @@ apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: ingress-pgadmin - annotations: - ingressClassName: traefik spec: - rules: - - host: pgadmin.kubernetes - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: service-pgadmin - port: - number: 80 + ingressClassName: tailscale + defaultBackend: + service: + name: service-pgadmin + port: + number: 80 + tls: + - hosts: + - pgadmin diff --git a/manifests/helm/longhorn.yaml b/manifests/helm/longhorn.yaml index e72e098..0a3952e 100644 --- a/manifests/helm/longhorn.yaml +++ b/manifests/helm/longhorn.yaml @@ -87,6 +87,22 @@ spec: --- apiVersion: networking.k8s.io/v1 kind: Ingress +metadata: + name: longhorn-ingress-tailscale + namespace: longhorn-system +spec: + ingressClassName: tailscale + defaultBackend: + service: + name: longhorn-frontend + port: + number: 80 + tls: + - hosts: + - longhorn +--- +apiVersion: networking.k8s.io/v1 +kind: Ingress metadata: name: longhorn-ingress namespace: longhorn-system diff --git a/manifests/immich/ingress.yaml b/manifests/immich/ingress.yaml index 9ccb756..d9d9e67 100644 --- a/manifests/immich/ingress.yaml +++ b/manifests/immich/ingress.yaml @@ -22,5 +22,19 @@ spec: name: immich-server port: name: http - - <<: *host - host: immich.thehellings.com +--- +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + namespace: immich + name: immich-ingress-tailscale +spec: + defaultBackend: + service: + name: immich-server + port: + name: http + ingressClassName: tailscale + tls: + - hosts: + - immich diff --git a/manifests/matrix/ingress.yaml b/manifests/matrix/ingress.yaml index 450bc05..9c6f684 100644 --- a/manifests/matrix/ingress.yaml +++ b/manifests/matrix/ingress.yaml @@ -1,21 +1,15 @@ apiVersion: networking.k8s.io/v1 kind: Ingress metadata: - name: dendrite-ingress - annotations: - ingressClassName: traefik + namespace: matrix + name: dendrite-ingress-tailscale spec: - rules: - - &host - host: matrix.kubernetes - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: dendrite - port: - number: 8008 - - <<: *host - host: matrix.thehellings.com + ingressClassName: tailscale + defaultBackend: + service: + name: dendrite + port: + number: 8008 + tls: + - hosts: + - matrix diff --git a/manifests/tailscale/apply.sh b/manifests/tailscale/apply.sh new file mode 100755 index 0000000..5ecb10f --- /dev/null +++ b/manifests/tailscale/apply.sh @@ -0,0 +1,15 @@ +#!/usr/bin/env bash + +helm repo add tailscale https://pkgs.tailscale.com/helmcharts + +helm repo update tailscale + +helm upgrade \ + --install \ + tailscale-operator \ + tailscale/tailscale-operator \ + --namespace=tailscale \ + --create-namespace \ + --set-string oauth.clientId="$(bw get username 'ffa188a4-63b2-4926-99f0-b33b0021a4f4')" \ + --set-string oauth.clientSecret="$(bw get password 'ffa188a4-63b2-4926-99f0-b33b0021a4f4')" \ + --wait diff --git a/modules/hm/gui/bookmarks.nix b/modules/hm/gui/bookmarks.nix index cbe88d0..abeba7c 100644 --- a/modules/hm/gui/bookmarks.nix +++ b/modules/hm/gui/bookmarks.nix @@ -208,14 +208,14 @@ bookmarks = [ { name = "Longhorn"; - url = "http://longhorn.kubernetes"; + url = "http://longhorn.shire-zebra.ts.net"; + } + { + name = "PGAdmin4"; + url = "http://pgadmin.shire-zebra.ts.net/"; } ]; } - { - name = "PGAdmin4"; - url = "http://pgadmin.kubernetes/"; - } { name = "Password Hash"; url = "https://unix4lyfe.org/crypt/"; From fdeef473dc56b4216a2e73958e63f81bc9cccbba Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 15 Aug 2025 22:59:11 -0500 Subject: [PATCH 065/124] Tweak nushell configuration --- home/baseline/nushell.nix | 1 + home/baseline/shell.nix | 15 ++++--- home/baseline/tools.nix | 89 ++++++++++++++++++++++----------------- 3 files changed, 59 insertions(+), 46 deletions(-) diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index 583cf7a..988d3d7 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -7,6 +7,7 @@ programs = { nushell = { enable = true; + environmentVariables = config.home.sessionVariables; extraConfig = '' use std/util "path add" path add ${config.home.homeDirectory}/src/bin diff --git a/home/baseline/shell.nix b/home/baseline/shell.nix index e53d7a4..2e7ba55 100644 --- a/home/baseline/shell.nix +++ b/home/baseline/shell.nix @@ -1,14 +1,15 @@ -{ config, lib, pkgs, ... }: +{ + config, + lib, + pkgs, + ... +}: { home = { - file = lib.mkIf pkgs.hostPlatform.isDarwin { - #"Library/Application Support/com.mitchellh.ghostty/config".source = "${config.home.homeDirectory}/.config/ghostty/config"; - "Library/Application Support/com.mitchellh.ghostty/config".source = config.xdg.configFile."ghostty/config".source; - }; sessionVariables = { AWS_SHARED_CREDENTIALS_FILE = "/run/agenix/cache-credentials"; CARAPACE_BRIDGES = "zsh,bash"; - EDITOR = "nvim"; + EDITOR = lib.getExe config.programs.neovim.package; GOPATH = "${config.home.homeDirectory}/src/go"; GOBIN = "${config.home.homeDirectory}/src/bin"; LIBMYSQL_ENABLE_CLEARTEXT_PLUGIN = "1"; @@ -60,7 +61,7 @@ enable = true; package = if pkgs.stdenv.hostPlatform.isDarwin then pkgs.ghostty-bin else pkgs.ghostty; settings = { - command = lib.getExe pkgs.nushell; + command = lib.getExe config.programs.nushell.package; font-family = "Hacker"; theme = "Dracula"; scrollback-limit = "1000000"; diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index a89614b..a653304 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -18,37 +18,43 @@ programs = { zellij = { enable = true; - attachExistingSession = true; enableZshIntegration = pkgs.stdenv.hostPlatform.isDarwin; settings = { default_shell = "xonsh"; plugins = { autolock = { _props.location = "https://github.com/fresh2dev/zellij-autolock/releases/download/0.2.2/zellij-autolock.wasm"; - _children = [ { - is_enabled = true; - } { - triggers = "nvim|vim|git"; - } { - reaction_seconds = "0.3"; - } { - print_to_log = true; - } ]; + _children = [ + { + is_enabled = true; + } + { + triggers = "nvim|vim|git"; + } + { + reaction_seconds = "0.3"; + } + { + print_to_log = true; + } + ]; }; }; - load_plugins.autolock = {}; + load_plugins.autolock = { }; keybinds = { normal._children = [ { bind = { _args = [ "Enter" ]; - _children = [ { - WriteChars = "\\u{000D}"; - MessagePlugin = { - _args = [ "autolock" ]; - _children = [{}]; - }; - } ]; + _children = [ + { + WriteChars = "\\u{000D}"; + MessagePlugin = { + _args = [ "autolock" ]; + _children = [ { } ]; + }; + } + ]; }; } { @@ -92,27 +98,32 @@ ]; # /locked shared_except = { _args = [ "locked" ]; - _children = [ { - bind = { - _args = [ "Ctrl h" ]; - MoveFocusOrTab._args = [ "Left" ]; - }; - } { - bind = { - _args = [ "Ctrl j" ]; - MoveFocus._args = [ "Down" ]; - }; - } { - bind = { - _args = [ "Ctrl k" ]; - MoveFocus._args = [ "Up" ]; - }; - } { - bind = { - _args = [ "Ctrl l" ]; - MoveFocusOrTab._args = [ "Right" ]; - }; - } ]; + _children = [ + { + bind = { + _args = [ "Ctrl h" ]; + MoveFocusOrTab._args = [ "Left" ]; + }; + } + { + bind = { + _args = [ "Ctrl j" ]; + MoveFocus._args = [ "Down" ]; + }; + } + { + bind = { + _args = [ "Ctrl k" ]; + MoveFocus._args = [ "Up" ]; + }; + } + { + bind = { + _args = [ "Ctrl l" ]; + MoveFocusOrTab._args = [ "Right" ]; + }; + } + ]; }; # /shared_except }; # /keybinds }; # /settings From 81c26f25c018e4c8e6d2a554af49749eba1a6df5 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sun, 17 Aug 2025 13:48:27 -0500 Subject: [PATCH 066/124] Make Exodus build things, too --- hosts/exodus/default.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/hosts/exodus/default.nix b/hosts/exodus/default.nix index 96a0826..9dcc7dc 100644 --- a/hosts/exodus/default.nix +++ b/hosts/exodus/default.nix @@ -28,8 +28,9 @@ podman.enable = true; print.enable = true; tailscale.enable = true; + runner.enable = true; vmdev = { - enable = true; + enable = false; system = "intel"; }; }; From 4ff64df35c750b3a728121c00e06f9d238a6a005 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 18 Aug 2025 02:04:06 -0500 Subject: [PATCH 067/124] Slight tweaks to gitlab-runner --- home/baseline/shell.nix | 1 + modules/nixos/gitlab-runner.nix | 3 ++- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/home/baseline/shell.nix b/home/baseline/shell.nix index 2e7ba55..0126e07 100644 --- a/home/baseline/shell.nix +++ b/home/baseline/shell.nix @@ -24,6 +24,7 @@ nixtest = "nixpkgs-review rev HEAD"; nixup = "nix flake lock update"; nixcopy = "nix copy --to \"s3://binary-cache/?profile=default&endpoint=nas.home%3A9000&scheme=http\""; + r = "run0"; s = "nix run \".#runserver\""; updateScript = "nix-shell maintainers/scripts/update.nix --argstr package"; diff --git a/modules/nixos/gitlab-runner.nix b/modules/nixos/gitlab-runner.nix index c190ac1..40f2d88 100644 --- a/modules/nixos/gitlab-runner.nix +++ b/modules/nixos/gitlab-runner.nix @@ -51,7 +51,7 @@ in virtualisation = { libvirtd = { - enable = true; + enable = lib.mkDefault true; allowedBridges = [ "br0" "virbr0" @@ -67,6 +67,7 @@ in users.extraGroups.vboxusers.members = [ "greg" ]; virtualisation = { + libvirtd.enable = false; virtualbox.host = { enable = true; enableExtensionPack = true; From 1802973ac21dc0a60dc5719fbaab32266e273d22 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 18 Aug 2025 02:04:21 -0500 Subject: [PATCH 068/124] Update nixpkgs pins --- flake.lock | 108 ++++++++++++++++++++++++++--------------------------- 1 file changed, 54 insertions(+), 54 deletions(-) diff --git a/flake.lock b/flake.lock index 0f70948..d9dabec 100644 --- a/flake.lock +++ b/flake.lock @@ -10,11 +10,11 @@ "systems": "systems" }, "locked": { - "lastModified": 1750173260, - "narHash": "sha256-9P1FziAwl5+3edkfFcr5HeGtQUtrSdk/MksX39GieoA=", + "lastModified": 1754433428, + "narHash": "sha256-NA/FT2hVhKDftbHSwVnoRTFhes62+7dxZbxj5Gxvghs=", "owner": "ryantm", "repo": "agenix", - "rev": "531beac616433bac6f9e2a19feb8e99a22a66baf", + "rev": "9edb1787864c4f59ae5074ad498b6272b3ec308d", "type": "github" }, "original": { @@ -74,11 +74,11 @@ ] }, "locked": { - "lastModified": 1751313918, - "narHash": "sha256-HsJM3XLa43WpG+665aGEh8iS8AfEwOIQWk3Mke3e7nk=", + "lastModified": 1755275010, + "narHash": "sha256-lEApCoWUEWh0Ifc3k1JdVjpMtFFXeL2gG1qvBnoRc2I=", "owner": "lnl7", "repo": "nix-darwin", - "rev": "e04a388232d9a6ba56967ce5b53a8a6f713cdfcf", + "rev": "7220b01d679e93ede8d7b25d6f392855b81dd475", "type": "github" }, "original": { @@ -117,11 +117,11 @@ "flake-compat": { "flake": false, "locked": { - "lastModified": 1696426674, - "narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=", + "lastModified": 1747046372, + "narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=", "owner": "edolstra", "repo": "flake-compat", - "rev": "0f9255e01c2351cc7d116c072cb317785dd33b33", + "rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885", "type": "github" }, "original": { @@ -166,11 +166,11 @@ "nixpkgs-lib": "nixpkgs-lib" }, "locked": { - "lastModified": 1753121425, - "narHash": "sha256-TVcTNvOeWWk1DXljFxVRp+E0tzG1LhrVjOGGoMHuXio=", + "lastModified": 1754487366, + "narHash": "sha256-pHYj8gUBapuUzKV/kN/tR3Zvqc7o6gdFB9XKXIp1SQ8=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "644e0fc48951a860279da645ba77fe4a6e814c5e", + "rev": "af66ad14b28a127c5c0f3bbb298218fc63528a18", "type": "github" }, "original": { @@ -187,11 +187,11 @@ ] }, "locked": { - "lastModified": 1753121425, - "narHash": "sha256-TVcTNvOeWWk1DXljFxVRp+E0tzG1LhrVjOGGoMHuXio=", + "lastModified": 1754487366, + "narHash": "sha256-pHYj8gUBapuUzKV/kN/tR3Zvqc7o6gdFB9XKXIp1SQ8=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "644e0fc48951a860279da645ba77fe4a6e814c5e", + "rev": "af66ad14b28a127c5c0f3bbb298218fc63528a18", "type": "github" }, "original": { @@ -303,11 +303,11 @@ ] }, "locked": { - "lastModified": 1753732062, - "narHash": "sha256-vojVM0SgFP8crFh1LDDXkzaI9/er/1cuRfbNPhfBHyc=", + "lastModified": 1755442500, + "narHash": "sha256-RHK4H6SWzkAtW/5WBHsyugaXJX25yr5y7FAZznxcBJs=", "owner": "nix-community", "repo": "home-manager", - "rev": "f49e872f55e36e67ebcb906ff65f86c7a1538f7c", + "rev": "d2ffdedfc39c591367b1ddf22b4ce107f029dcc3", "type": "github" }, "original": { @@ -345,11 +345,11 @@ "nixpkgs": "nixpkgs_2" }, "locked": { - "lastModified": 1750779888, - "narHash": "sha256-wibppH3g/E2lxU43ZQHC5yA/7kIKLGxVEnsnVK1BtRg=", + "lastModified": 1755446520, + "narHash": "sha256-I0Ok1OGDwc1jPd8cs2VvAYZsHriUVFGIUqW+7uSsOUM=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "16ec914f6fb6f599ce988427d9d94efddf25fe6d", + "rev": "4b04db83821b819bbbe32ed0a025b31e7971f22e", "type": "github" }, "original": { @@ -388,11 +388,11 @@ }, "nix-hardware": { "locked": { - "lastModified": 1753122741, - "narHash": "sha256-nFxE8lk9JvGelxClCmwuJYftbHqwnc01dRN4DVLUroM=", + "lastModified": 1755330281, + "narHash": "sha256-aJHFJWP9AuI8jUGzI77LYcSlkA9wJnOIg4ZqftwNGXA=", "owner": "nixos", "repo": "nixos-hardware", - "rev": "cc66fddc6cb04ab479a1bb062f4d4da27c936a22", + "rev": "3dac8a872557e0ca8c083cdcfc2f218d18e113b0", "type": "github" }, "original": { @@ -455,11 +455,11 @@ }, "nixpkgs-lib": { "locked": { - "lastModified": 1751159883, - "narHash": "sha256-urW/Ylk9FIfvXfliA1ywh75yszAbiTEVgpPeinFyVZo=", + "lastModified": 1753579242, + "narHash": "sha256-zvaMGVn14/Zz8hnp4VWT9xVnhc8vuL3TStRqwk22biA=", "owner": "nix-community", "repo": "nixpkgs.lib", - "rev": "14a40a1d7fb9afa4739275ac642ed7301a9ba1ab", + "rev": "0f36c44e01a6129be94e3ade315a5883f0228a6e", "type": "github" }, "original": { @@ -516,11 +516,11 @@ }, "nixpkgs_2": { "locked": { - "lastModified": 1730768919, - "narHash": "sha256-8AKquNnnSaJRXZxc5YmF/WfmxiHX6MMZZasRP6RRQkE=", + "lastModified": 1754340878, + "narHash": "sha256-lgmUyVQL9tSnvvIvBp7x1euhkkCho7n3TMzgjdvgPoU=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "a04d33c0c3f1a59a2c1cb0c6e34cd24500e5a1dc", + "rev": "cab778239e705082fe97bb4990e0d24c50924c04", "type": "github" }, "original": { @@ -532,11 +532,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1753549186, - "narHash": "sha256-Znl7rzuxKg/Mdm6AhimcKynM7V3YeNDIcLjBuoBcmNs=", + "lastModified": 1755186698, + "narHash": "sha256-wNO3+Ks2jZJ4nTHMuks+cxAiVBGNuEBXsT29Bz6HASo=", "owner": "nixos", "repo": "nixpkgs", - "rev": "17f6bd177404d6d43017595c5264756764444ab8", + "rev": "fbcf476f790d8a217c3eab4e12033dc4a0f6d23c", "type": "github" }, "original": { @@ -564,11 +564,11 @@ }, "nixunstable": { "locked": { - "lastModified": 1753549186, - "narHash": "sha256-Znl7rzuxKg/Mdm6AhimcKynM7V3YeNDIcLjBuoBcmNs=", + "lastModified": 1755186698, + "narHash": "sha256-wNO3+Ks2jZJ4nTHMuks+cxAiVBGNuEBXsT29Bz6HASo=", "owner": "nixos", "repo": "nixpkgs", - "rev": "17f6bd177404d6d43017595c5264756764444ab8", + "rev": "fbcf476f790d8a217c3eab4e12033dc4a0f6d23c", "type": "github" }, "original": { @@ -588,11 +588,11 @@ "systems": "systems_4" }, "locked": { - "lastModified": 1753706533, - "narHash": "sha256-ZNyVwyj+4qvaOT/gQWfNypP8qtHmXtt02D9WDZH4IPU=", + "lastModified": 1755095763, + "narHash": "sha256-cFwtMaONA4uKYk/rBrmFvIAQieZxZytoprzIblTn1HA=", "owner": "nix-community", "repo": "nixvim", - "rev": "e1aa35fb04047df11a9c1ab539a0bac35ddad509", + "rev": "ecc7880e00a2a735074243d8a664a931d73beace", "type": "github" }, "original": { @@ -608,11 +608,11 @@ "nixpkgs": "nixpkgs_3" }, "locked": { - "lastModified": 1753746745, - "narHash": "sha256-1Ii4RX2gUAp5KtdQOLokBMJ0dKeqabAeiS18NirGI6o=", + "lastModified": 1755452770, + "narHash": "sha256-oc8xrqvVIoDxbfTlbkE1XQ7O88TgNZn5FOZKLiuIEmg=", "owner": "nix-community", "repo": "NUR", - "rev": "678f454f7f1b884cea5a8b266937969693419acf", + "rev": "eab62298402c7cdfdefda647a4046befa3a84051", "type": "github" }, "original": { @@ -631,11 +631,11 @@ ] }, "locked": { - "lastModified": 1753450833, - "narHash": "sha256-Pmpke0JtLRzgdlwDC5a+aiLVZ11JPUO5Bcqkj0nHE/k=", + "lastModified": 1754301638, + "narHash": "sha256-aRgzcPDd2axHFOuMlPLuzmDptUM2JU8mUL3jfgbBeyc=", "owner": "NuschtOS", "repo": "search", - "rev": "40987cc1a24feba378438d691f87c52819f7bd75", + "rev": "a60091045273484c040a91f5c229ba298f8ecc27", "type": "github" }, "original": { @@ -652,11 +652,11 @@ "utils": "utils" }, "locked": { - "lastModified": 1751538533, - "narHash": "sha256-aNB6A0+azhP/Wt9fFQslHMeQHlTYoz8Y/1cI4XqzrP0=", + "lastModified": 1754428470, + "narHash": "sha256-Sxf8gf+vfGeFaJMW3D+8pwH/+WwYTQOg47Lrm42+kTc=", "owner": "SaumonNet", "repo": "proxmox-nixos", - "rev": "bfe830d4d3fc055b8d157313a3ec2fa69ded5d4e", + "rev": "6faed2845ef5f0bb05c9519b75097bbe7fb39327", "type": "github" }, "original": { @@ -797,11 +797,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1753669528, - "narHash": "sha256-NyDesHCYBB+VGMaTUKj6GxLeVMcpc09OI6CIxVVPVPI=", + "lastModified": 1755396877, + "narHash": "sha256-92gZRDz3zEsodraI0ZxPzZrpjSqc2qjxTW9HOflzKFw=", "owner": "nix-community", "repo": "nix-vscode-extensions", - "rev": "c258332ac73118ccd664f24c2730dc66da97eb8e", + "rev": "0cf076c0bafbe7cbd33a3b7377ed24827674e8be", "type": "github" }, "original": { @@ -818,11 +818,11 @@ ] }, "locked": { - "lastModified": 1753704990, - "narHash": "sha256-5E14xuNWy2Un1nFR55k68hgbnD8U2x/rE5DXJtYKusw=", + "lastModified": 1755261305, + "narHash": "sha256-EOqCupB5X5WoGVHVcfOZcqy0SbKWNuY3kq+lj1wHdu8=", "owner": "nix-community", "repo": "NixOS-WSL", - "rev": "58c814cc6d4a789191f9c12e18277107144b0c91", + "rev": "203a7b463f307c60026136dd1191d9001c43457f", "type": "github" }, "original": { From 7aabe6246eec0ae3a9e1a21ad47abab7cf45ee1e Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 18 Aug 2025 02:06:03 -0500 Subject: [PATCH 069/124] Update nushell file format --- home/baseline/nushell.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index 988d3d7..08f6c48 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -18,6 +18,7 @@ settings = { buffer_editor = lib.getExe config.programs.nixvim.package; "history.isolation" = true; + "history.file_format" = "sqlite"; }; }; }; From c96560f22de51fc66adbcd09b1ac06fc67fa32ce Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 19 Aug 2025 15:09:15 -0500 Subject: [PATCH 070/124] Add notunes --- darwin/hosts/ivr/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/darwin/hosts/ivr/default.nix b/darwin/hosts/ivr/default.nix index 230ca6b..a71a6df 100644 --- a/darwin/hosts/ivr/default.nix +++ b/darwin/hosts/ivr/default.nix @@ -43,6 +43,7 @@ in "firefox" "microsoft-teams" "mysqlworkbench" + "notunes" "onlyoffice" "pgadmin4" "podman-desktop" From a2082d3ffe1d7b058f4643c0529e98ebf3163f6a Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 19 Aug 2025 15:09:33 -0500 Subject: [PATCH 071/124] Rename older modules version --- home/home.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/home/home.nix b/home/home.nix index 3d82e55..85102ea 100644 --- a/home/home.nix +++ b/home/home.nix @@ -17,7 +17,7 @@ let in { imports = [ - top.nixvimunstable.homeManagerModules.nixvim + top.nixvimunstable.homeModules.nixvim top.self.modules.homeManagerModule ./baseline ] ++ lib.optionals (builtins.pathExists ./hosts/${host}) [ ./hosts/${host} ]; From 13b4c26e6659607609938192312dd829db0028c9 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 19 Aug 2025 15:09:42 -0500 Subject: [PATCH 072/124] Add VPN script --- home/baseline/nushell.nix | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index 08f6c48..5b66170 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -1,8 +1,28 @@ { config, lib, + pkgs, ... }: +let + vpn = pkgs.writeText "vpn" '' + on run argv + ignoring application responses + tell application "Viscosity" + connect "350Main" + end tell + end ignoring + + delay 1.0 + + activate application "Viscosity" + tell application "System Events" to keystroke item 1 of argv + tell application "System Events" to keystroke tab + tell application "System Events" to keystroke item 2 of argv + tell application "System Events" to keystroke return + end run + ''; +in { programs = { nushell = { @@ -14,6 +34,16 @@ path add /opt/homebrew/bin path add /run/current-system/sw/bin path add ${config.home.homeDirectory}/.nix-profile/bin + + def vpn [] { + if "BW_SESSION" not-in $env { + $env.BW_SESSION = ^bw unlock --raw + } + let username = ^bw get username f7351f9c-b25b-4317-8352-affc00da4644 + let password = ^bw get password f7351f9c-b25b-4317-8352-affc00da4644 + let otp = ^bw get totp 10371487-7f40-4b08-9a45-b33e00de318b + osascript ${vpn} $username $"($password)($otp)" + } ''; settings = { buffer_editor = lib.getExe config.programs.nixvim.package; From a90ddf9dce1daa3e99ee88e20f65afa9fc59f6c5 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 19 Aug 2025 15:12:09 -0500 Subject: [PATCH 073/124] Add slight delays to VPN --- home/baseline/nushell.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index 5b66170..a324c75 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -17,8 +17,11 @@ let activate application "Viscosity" tell application "System Events" to keystroke item 1 of argv + delay 0.1 tell application "System Events" to keystroke tab + delay 0.1 tell application "System Events" to keystroke item 2 of argv + delay 0.1 tell application "System Events" to keystroke return end run ''; From 92237b2108ec0a8e8edf7c1b931dafdee142202d Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 19 Aug 2025 15:43:55 -0500 Subject: [PATCH 074/124] More nushell aliases Propagate the environment variables out of the functions when appropriate Add rebuild command Add deploy function --- home/baseline/nushell.nix | 30 +++++++++++++++++++++++++++++- 1 file changed, 29 insertions(+), 1 deletion(-) diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index a324c75..617a4d2 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -38,15 +38,43 @@ in path add /run/current-system/sw/bin path add ${config.home.homeDirectory}/.nix-profile/bin - def vpn [] { + def --env unlock [] { if "BW_SESSION" not-in $env { $env.BW_SESSION = ^bw unlock --raw } + } + + def --env vpn [] { + unlock let username = ^bw get username f7351f9c-b25b-4317-8352-affc00da4644 let password = ^bw get password f7351f9c-b25b-4317-8352-affc00da4644 let otp = ^bw get totp 10371487-7f40-4b08-9a45-b33e00de318b osascript ${vpn} $username $"($password)($otp)" } + + def rebuild [] { + if (uname | get operating-system) == "Darwin" { + sudo darwin-rebuild switch + } else { + let hostname = uname | get nodename + let build = ^nom build $"/etc/nixos#nixosConfigurations.($hostname).config.system.build.toplevel" | complete + if build.exit_code == 0 { + nvd diff /run/current-system result + sudo nixos-rebuild switch + } + } + } + + def deploy [ $host: string, $build: string = "" ] { + mut buildhost = $build + if $build == "" { + $buildhost = $host + } + if $buildhost == "linode" { + $buildhost = "isaiah" + } + nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host $host --build-host $buildhost + } ''; settings = { buffer_editor = lib.getExe config.programs.nixvim.package; From b860a6d2a6ac9cfdfa208b8b0cfab773d626cf79 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 21 Aug 2025 17:59:38 -0500 Subject: [PATCH 075/124] Add virtualbox to IVR --- darwin/hosts/ivr/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/darwin/hosts/ivr/default.nix b/darwin/hosts/ivr/default.nix index a71a6df..4cad7cd 100644 --- a/darwin/hosts/ivr/default.nix +++ b/darwin/hosts/ivr/default.nix @@ -50,6 +50,7 @@ in "tabby" "twine" "vagrant" + "virtualbox" "visual-studio-code" "zed" "zoho-workdrive" From df5d81d092bda62299a14ca42e53c7cc97c033d1 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sat, 23 Aug 2025 01:48:05 -0500 Subject: [PATCH 076/124] Update Isaiah for new harddrive setup --- hosts/isaiah/default.nix | 1 - hosts/isaiah/hardware-configuration.nix | 59 +++++++++++++++++++------ 2 files changed, 45 insertions(+), 15 deletions(-) diff --git a/hosts/isaiah/default.nix b/hosts/isaiah/default.nix index a6d4645..400184c 100644 --- a/hosts/isaiah/default.nix +++ b/hosts/isaiah/default.nix @@ -28,7 +28,6 @@ }; systemd-boot = { enable = true; - configurationLimit = 10; }; }; supportedFilesystems = [ "ntfs" ]; diff --git a/hosts/isaiah/hardware-configuration.nix b/hosts/isaiah/hardware-configuration.nix index 9c6d38e..8c3161a 100644 --- a/hosts/isaiah/hardware-configuration.nix +++ b/hosts/isaiah/hardware-configuration.nix @@ -5,24 +5,55 @@ config, lib, modulesPath, + pkgs, ... }: { imports = [ (modulesPath + "/installer/scan/not-detected.nix") ]; - boot.initrd.availableKernelModules = [ - "nvme" - "xhci_pci" - "ahci" - "usb_storage" - "usbhid" - "sd_mod" - "sr_mod" - ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ "kvm-amd" ]; - boot.extraModulePackages = [ ]; + boot = { + extraModulePackages = [ ]; + kernelModules = [ "kvm-amd" ]; + initrd = { + availableKernelModules = [ + "nvme" + "xhci_pci" + "ahci" + "usb_storage" + "usbhid" + "sd_mod" + "sr_mod" + ]; + kernelModules = [ ]; + }; + loader = { + timeout = 15; + systemd-boot = { + enable = true; + configurationLimit = 20; + extraEntries = { + "Win2.conf" = ( + lib.strings.concatStringsSep "\n" [ + "title Windows 11" + "efi /shellx64.efi" + "options -nointerrupt -noconsolein -noconsoleout windows11.nsh" + ] + ); + "Shell.conf" = ( + lib.strings.concatStringsSep "\n" [ + "title EFI Shell" + "efi /shell.efi" + ] + ); + }; + extraFiles = { + "windows11.nsh" = (pkgs.writeText "windows11.nsh" (lib.strings.concatStringsSep "\n" [ ])); + "shell.efi" = "${pkgs.edk2-uefi-shell}/shell.efi"; + }; + }; + }; + }; fileSystems."/" = { device = "/dev/disk/by-uuid/714744ca-dd9d-4713-b571-c6ccfbf56d79"; @@ -37,12 +68,12 @@ }; fileSystems."/boot" = { - device = "/dev/disk/by-uuid/29E7-E20C"; + device = "/dev/disk/by-uuid/4A92-3E4B"; fsType = "vfat"; }; fileSystems."/myvol" = { - device = "/dev/nvme0n1p1"; + device = "/dev/disk/by-uuid/714744ca-dd9d-4713-b571-c6ccfbf56d79"; fsType = "btrfs"; }; From 568aef0fdb793b5b45fdffb29b6a90a199317772 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 26 Aug 2025 19:57:26 -0500 Subject: [PATCH 077/124] Add disk space for pgvector --- manifests/immich/database.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifests/immich/database.yaml b/manifests/immich/database.yaml index 154151f..5981cf4 100644 --- a/manifests/immich/database.yaml +++ b/manifests/immich/database.yaml @@ -7,7 +7,7 @@ spec: imageName: "ghcr.io/tensorchord/cloudnative-pgvecto.rs:16-v0.3.0" instances: 1 storage: - size: 30Gi + size: 40Gi primaryUpdateStrategy: unsupervised postgresql: shared_preload_libraries: From 399813927972c71da0dd7f4dc736bf817c391bc9 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 26 Aug 2025 20:20:35 -0500 Subject: [PATCH 078/124] Remove old mount from Zeke --- hosts/zeke/hardware-configuration.nix | 4 ---- 1 file changed, 4 deletions(-) diff --git a/hosts/zeke/hardware-configuration.nix b/hosts/zeke/hardware-configuration.nix index ad8d509..a2221ff 100644 --- a/hosts/zeke/hardware-configuration.nix +++ b/hosts/zeke/hardware-configuration.nix @@ -33,10 +33,6 @@ device = "/dev/nvme0n1p1"; fsType = "auto"; }; - "/windows11" = { - device = "/dev/nvme1n1p2"; - fsType = "ntfs-3g"; - }; }; swapDevices = [ ]; From e07c1d54f9047e736f5c43fdefb90e164d29d713 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 26 Aug 2025 20:44:37 -0500 Subject: [PATCH 079/124] Increase disk space for Postgres --- manifests/databases/postgres-cluster.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifests/databases/postgres-cluster.yaml b/manifests/databases/postgres-cluster.yaml index 74efbf5..5ec9aa9 100644 --- a/manifests/databases/postgres-cluster.yaml +++ b/manifests/databases/postgres-cluster.yaml @@ -5,7 +5,7 @@ metadata: spec: instances: 3 storage: - size: 10Gi + size: 20Gi primaryUpdateStrategy: unsupervised managed: From d701cd7b3e4fac6e568af3142c1ec6ac89ce3d65 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 27 Aug 2025 10:32:33 -0500 Subject: [PATCH 080/124] Add wget to img-bitwarden --- pkgs/img-bitwarden.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/img-bitwarden.nix b/pkgs/img-bitwarden.nix index d57e7d6..9ef65e1 100644 --- a/pkgs/img-bitwarden.nix +++ b/pkgs/img-bitwarden.nix @@ -3,6 +3,7 @@ cacert, dockerTools, lib, + wget, writeShellApplication, ... }: @@ -12,6 +13,7 @@ dockerTools.buildLayeredImage { contents = [ dockerTools.binSh dockerTools.caCertificates + wget ]; config = { Cmd = [ From 53f868dc1e5b6cc5692281d17d1d024c50b3768c Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 27 Aug 2025 10:33:04 -0500 Subject: [PATCH 081/124] Barman plugin requires cert-manager --- manifests/apply.sh | 1 + 1 file changed, 1 insertion(+) diff --git a/manifests/apply.sh b/manifests/apply.sh index b9dea74..68f813a 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -21,6 +21,7 @@ kubectl annotate nodes --overwrite zeke 'node.longhorn.io/default-disks-config=[ { "path": "/var/lib/longhorn", "allowScheduling" : trues, "tags": ["ssd", "fast"]} ]' +kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.18.2/cert-manager.yaml kubectl apply -f helm/flux.yaml sleep 5 kubectl apply -f helm/kyverno.yaml From 743c1fede18e66de951f83ac0f0b6a0f3bc4e027 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Wed, 27 Aug 2025 10:33:32 -0500 Subject: [PATCH 082/124] Add BitWarden escape hatch image --- manifests/bitwarden/deployment.yaml | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/manifests/bitwarden/deployment.yaml b/manifests/bitwarden/deployment.yaml index 5c48996..3a3fa7c 100644 --- a/manifests/bitwarden/deployment.yaml +++ b/manifests/bitwarden/deployment.yaml @@ -21,7 +21,11 @@ spec: spec: containers: - name: bitwarden-cli - image: "registry.thehellings.com/greg/nixos-config/img-bitwarden:latest" + # Since my gitlab instance depends on the database hosted in k3s, and the + # database depends on this image, I need a way to bootstrap the system if + # I am doing disaster recovery. And this is it. + image: "ghcr.io/greg-hellings/nixos-config/img-bitwarden:latest" + #image: "registry.thehellings.com/greg/nixos-config/img-bitwarden:latest" imagePullPolicy: Always env: - name: BW_CLIENTID From 8119b9e0a52559fa1bc166592828079b757f476e Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 26 Aug 2025 09:53:54 -0500 Subject: [PATCH 083/124] Add find file alias to nushell --- home/baseline/nushell.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index 617a4d2..5c693f5 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -75,6 +75,10 @@ in } nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host $host --build-host $buildhost } + + def ff [ $file: string ] { + ls **/* | where name =~ $file + } ''; settings = { buffer_editor = lib.getExe config.programs.nixvim.package; From 0e6f3ada799aeee50b936e1fcc5b525a5d4cc747 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 9 Sep 2025 23:26:42 -0500 Subject: [PATCH 084/124] Isaiah is currently down --- hosts/genesis/net/hosts | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hosts/genesis/net/hosts b/hosts/genesis/net/hosts index 00c6b9e..da17425 100644 --- a/hosts/genesis/net/hosts +++ b/hosts/genesis/net/hosts @@ -36,8 +36,8 @@ 100.88.91.27 genesis.home smart.home zwave.home nixcache.home gitcache.home dashy.home uptime.home speed.home 100.91.131.66 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan 100.68.203.1 hosea.home hosea.shire-zebra.ts.net -100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes postgres.kubernetes longhorn.kubernetes -100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes immich.kubernetes +100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes longhorn.kubernetes +100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes immich.kubernetes postgres.kubernetes 100.90.74.19 zeke.home 100.115.57.8 linode.home 100.65.5.38 matrix.home matrix.shire-zebra.ts.net From 6ab984cacf5b54ca3f6cccf8f1822db997176f34 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 9 Sep 2025 23:27:48 -0500 Subject: [PATCH 085/124] Make cluster slightly less robust --- manifests/databases/postgres-cluster.yaml | 61 +++++++++++++++++------ manifests/databases/secrets.yaml | 4 +- manifests/helm/longhorn.yaml | 6 +++ 3 files changed, 53 insertions(+), 18 deletions(-) diff --git a/manifests/databases/postgres-cluster.yaml b/manifests/databases/postgres-cluster.yaml index 5ec9aa9..554959d 100644 --- a/manifests/databases/postgres-cluster.yaml +++ b/manifests/databases/postgres-cluster.yaml @@ -3,7 +3,8 @@ kind: Cluster metadata: name: postgres spec: - instances: 3 + instances: 2 + enablePDB: false storage: size: 20Gi primaryUpdateStrategy: unsupervised @@ -31,20 +32,48 @@ spec: superuser: false passwordSecret: name: postgres-user-matrix - backup: - retentionPolicy: "30d" - barmanObjectStore: - destinationPath: "s3://k3sbackup/postgres" - endpointURL: "http://s3.thehellings.lan:9000/" - s3Credentials: - accessKeyId: - name: k3sbackup - key: username - secretAccessKey: - name: k3sbackup - key: password - wal: - compression: gzip + + plugins: + - name: barman-cloud.cloudnative-pg.io + isWALArchiver: false + parameters: + barmanObjectName: k3sbackup-objectstore + + # Use this as the target of the bootstrap recovery process + # It is important that the `externalClusters` serverName matches + # the old name of the original cluster that you are upgrading. + # When restoring, set the targetTime to the latest backup that you + # want to restore to +# bootstrap: +# recovery: +# source: origin +# recoveryTarget: +# targetTime: "2025-08-25 19:00:40+05" +# externalClusters: +# - name: origin +# plugin: +# name: barman-cloud.cloudnative-pg.io +# parameters: +# barmanObjectName: k3sbackup-objectstore +# serverName: postgres +--- +apiVersion: barmancloud.cnpg.io/v1 +kind: ObjectStore +metadata: + name: k3sbackup-objectstore +spec: + configuration: + destinationPath: "s3://k3sbackup/postgres" + endpointURL: "http://s3.thehellings.lan:9000/" + s3Credentials: + accessKeyId: + name: k3sbackup-secret + key: username + secretAccessKey: + name: k3sbackup-secret + key: password + wal: + compression: gzip --- apiVersion: postgresql.cnpg.io/v1 kind: ScheduledBackup @@ -52,7 +81,7 @@ metadata: name: postgres-backup spec: immediate: true # Create one when this is added to the cluster - schedule: "0 0 0 * * *" # Midnight, nightly + schedule: "0 1 0 * * *" # 1AM, nightly backupOwnerReference: self cluster: name: postgres diff --git a/manifests/databases/secrets.yaml b/manifests/databases/secrets.yaml index bca61d8..946b660 100644 --- a/manifests/databases/secrets.yaml +++ b/manifests/databases/secrets.yaml @@ -103,11 +103,11 @@ spec: apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: - name: k3sbackup + name: k3sbackup-externalsecret namespace: db spec: target: - name: k3sbackup + name: k3sbackup-secret deletionPolicy: Delete template: type: Opaque diff --git a/manifests/helm/longhorn.yaml b/manifests/helm/longhorn.yaml index 0a3952e..5f94899 100644 --- a/manifests/helm/longhorn.yaml +++ b/manifests/helm/longhorn.yaml @@ -30,6 +30,12 @@ spec: values: defaultSettings: createDefaultDiskLabeledNodes: true + persistence: + # This should go back to 3 when I have more cluster + defaultClassReplicaCount: 2 + defaultSettings: + # This should go back to null when I have more cluster + replicaSoftAntiAffinity: true --- apiVersion: v1 kind: ConfigMap From c8eaa02ebb2093a0bb1a8045e35f78dac9cecd70 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 11:26:37 -0500 Subject: [PATCH 086/124] Suppress MOTD banners --- home/baseline/ssh.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/home/baseline/ssh.nix b/home/baseline/ssh.nix index 1fe13c1..c2c79df 100644 --- a/home/baseline/ssh.nix +++ b/home/baseline/ssh.nix @@ -27,6 +27,7 @@ "*" = { dynamicForwards = [ { port = 10240; } ]; + extraOptions.LogLevel = "error"; }; "10.42.1.4" = lib.hm.dag.entryBefore [ "10.42.*" ] nas; From 6e7c488de14863cf9726997a9f12bc4a6d62ee8b Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 12:15:39 -0500 Subject: [PATCH 087/124] Add nu-shell functions --- home/baseline/nushell.nix | 34 +------------------------- home/baseline/nushell/functions.nu | 38 ++++++++++++++++++++++++++++++ 2 files changed, 39 insertions(+), 33 deletions(-) create mode 100644 home/baseline/nushell/functions.nu diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index 5c693f5..13cae03 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -38,12 +38,6 @@ in path add /run/current-system/sw/bin path add ${config.home.homeDirectory}/.nix-profile/bin - def --env unlock [] { - if "BW_SESSION" not-in $env { - $env.BW_SESSION = ^bw unlock --raw - } - } - def --env vpn [] { unlock let username = ^bw get username f7351f9c-b25b-4317-8352-affc00da4644 @@ -52,33 +46,7 @@ in osascript ${vpn} $username $"($password)($otp)" } - def rebuild [] { - if (uname | get operating-system) == "Darwin" { - sudo darwin-rebuild switch - } else { - let hostname = uname | get nodename - let build = ^nom build $"/etc/nixos#nixosConfigurations.($hostname).config.system.build.toplevel" | complete - if build.exit_code == 0 { - nvd diff /run/current-system result - sudo nixos-rebuild switch - } - } - } - - def deploy [ $host: string, $build: string = "" ] { - mut buildhost = $build - if $build == "" { - $buildhost = $host - } - if $buildhost == "linode" { - $buildhost = "isaiah" - } - nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host $host --build-host $buildhost - } - - def ff [ $file: string ] { - ls **/* | where name =~ $file - } + source ${./nushell/functions.nu} ''; settings = { buffer_editor = lib.getExe config.programs.nixvim.package; diff --git a/home/baseline/nushell/functions.nu b/home/baseline/nushell/functions.nu new file mode 100644 index 0000000..ea5eca2 --- /dev/null +++ b/home/baseline/nushell/functions.nu @@ -0,0 +1,38 @@ +def par-map [ items: list, c: closure ] { + let results = $items | par-each -k $c + $items | enumerate | reduce -f {} {|e, a| $a | upsert $e.item { $results | get $e.index }} +} + +def --env unlock [] { + if "BW_SESSION" not-in $env { + $env.BW_SESSION = ^bw unlock --raw + } +} + +def rebuild [] { + if (uname | get operating-system) == "Darwin" { + sudo darwin-rebuild switch + } else { + let hostname = uname | get nodename + let build = ^nom build $"/etc/nixos#nixosConfigurations.($hostname).config.system.build.toplevel" | complete + if build.exit_code == 0 { + nvd diff /run/current-system result + sudo nixos-rebuild switch + } + } +} + +def deploy [ $host: string, $build: string = "" ] { + mut buildhost = $build + if $build == "" { + $buildhost = $host + } + if $buildhost == "linode" { + $buildhost = "isaiah" + } + nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host $host --build-host $buildhost +} + +def ff [ $file: string ] { + ls **/* | where name =~ $file +} From 4311585a4e2cc6bd0eedd540038cdd52ad91761a Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 21:11:31 -0500 Subject: [PATCH 088/124] Enable nushell language server --- home/baseline/vim/config.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/home/baseline/vim/config.nix b/home/baseline/vim/config.nix index 69f0998..80369e0 100644 --- a/home/baseline/vim/config.nix +++ b/home/baseline/vim/config.nix @@ -120,6 +120,7 @@ gopls.enable = true; html.enable = true; nixd.enable = true; + nushell.enable = true; pylsp.enable = true; pyright.enable = true; rust_analyzer = { From 1a284e0e5fbf2fb0c0ad5ad4fa54824811d10976 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 21:39:34 -0500 Subject: [PATCH 089/124] Slight improvements to legibility of results --- home/baseline/nushell/functions.nu | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/home/baseline/nushell/functions.nu b/home/baseline/nushell/functions.nu index ea5eca2..1660991 100644 --- a/home/baseline/nushell/functions.nu +++ b/home/baseline/nushell/functions.nu @@ -1,3 +1,5 @@ +let servers = [isaiah jeremiah zeke genesis vm-gitlab vm-jellyfin] + def par-map [ items: list, c: closure ] { let results = $items | par-each -k $c $items | enumerate | reduce -f {} {|e, a| $a | upsert $e.item { $results | get $e.index }} @@ -30,9 +32,13 @@ def deploy [ $host: string, $build: string = "" ] { if $buildhost == "linode" { $buildhost = "isaiah" } - nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host $host --build-host $buildhost + nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host $host --build-host $buildhost | complete } def ff [ $file: string ] { ls **/* | where name =~ $file } + +def update_all [] { + par-map $servers {|e| deploy $e} | explore +} From ce0fd0102a20c52102243ea405f254826549a3ba Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 5 Sep 2025 13:04:10 -0500 Subject: [PATCH 090/124] Move node labels to Nix --- manifests/apply.sh | 4 ---- modules/nixos/kubernetes.nix | 1 + 2 files changed, 1 insertion(+), 4 deletions(-) diff --git a/manifests/apply.sh b/manifests/apply.sh index 68f813a..622b8fe 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -6,10 +6,6 @@ SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )" # Change to the script directory cd "$SCRIPT_DIR" -# First, label the nodes to control Longhorn rollout -for n in isaiah jeremiah zeke; do - kubectl label nodes "${n}" "node.longhorn.io/create-default-disk=config" -done # Now, configure longhorn settings for each node kubectl annotate nodes --overwrite isaiah 'node.longhorn.io/default-disks-config=[ { "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]} diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index d88a859..7a36810 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -78,6 +78,7 @@ in "--write-kubeconfig-mode 0640" "--write-kubeconfig-group kubeconfig" "--resolv-conf=/etc/resolv.conf" + "--node-label node.longhorn.io/create-default-disk=config" "--tls-san ${config.networking.hostName}.home" "--tls-san ${config.networking.hostName}.thehellings.lan" "--tls-san ${config.networking.hostName}.shire-zebra.ts.net" From a573f12221b90d5e95567c472a5a4c7733f53756 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 5 Sep 2025 13:13:30 -0500 Subject: [PATCH 091/124] Move node annotations to Nix --- manifests/apply.sh | 11 ----------- manifests/nodes.yaml | 29 +++++++++++++++++++++++++++++ modules/nixos/kubernetes.nix | 7 +++++-- 3 files changed, 34 insertions(+), 13 deletions(-) create mode 100644 manifests/nodes.yaml diff --git a/manifests/apply.sh b/manifests/apply.sh index 622b8fe..3cd6c81 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -6,17 +6,6 @@ SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )" # Change to the script directory cd "$SCRIPT_DIR" -# Now, configure longhorn settings for each node -kubectl annotate nodes --overwrite isaiah 'node.longhorn.io/default-disks-config=[ - { "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]} -]' -kubectl annotate nodes --overwrite jeremiah 'node.longhorn.io/default-disks-config=[ - { "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]} -]' -kubectl annotate nodes --overwrite zeke 'node.longhorn.io/default-disks-config=[ - { "path": "/var/lib/longhorn", "allowScheduling" : trues, "tags": ["ssd", "fast"]} -]' - kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.18.2/cert-manager.yaml kubectl apply -f helm/flux.yaml sleep 5 diff --git a/manifests/nodes.yaml b/manifests/nodes.yaml new file mode 100644 index 0000000..379f0bd --- /dev/null +++ b/manifests/nodes.yaml @@ -0,0 +1,29 @@ +apiVersion: v1 +kind: Node +metadata: + name: isaiah + annotations: + "node.longhorn.io/default-disks-config": |- + [ + { "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]} + ] +--- +apiVersion: v1 +kind: Node +metadata: + name: jeremiah + annotations: + "node.longhorn.io/default-disks-config": |- + [ + { "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]} + ] +--- +apiVersion: v1 +kind: Node +metadata: + name: zeke + annotations: + "node.longhorn.io/default-disks-config": |- + [ + { "path": "/var/lib/longhorn", "allowScheduling" : trues, "tags": ["ssd", "fast"]} + ] diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index 7a36810..79ce4f2 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -70,8 +70,6 @@ in services = { k3s = { enable = true; - role = if cfg.agentOnly then "agent" else "server"; - tokenFile = config.age.secrets.kubernetesToken.path; extraFlags = [ "--cluster-cidr=10.211.0.0/16" "--service-cidr=10.221.0.0/16" @@ -83,7 +81,12 @@ in "--tls-san ${config.networking.hostName}.thehellings.lan" "--tls-san ${config.networking.hostName}.shire-zebra.ts.net" ]; + manifests = { + node-annotations.content = ../../manifests/nodes.yaml; + }; + role = if cfg.agentOnly then "agent" else "server"; serverAddr = lib.mkIf (config.networking.hostName != "isaiah") "https://isaiah.home:6443"; + tokenFile = config.age.secrets.kubernetesToken.path; }; keepalived = let From 305ca30ad5e185806c42e4b950d2ac148df9ecc4 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 5 Sep 2025 13:18:59 -0500 Subject: [PATCH 092/124] Add cert-manager to startup process --- manifests/apply.sh | 1 - modules/nixos/kubernetes.nix | 4 ++++ 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/manifests/apply.sh b/manifests/apply.sh index 3cd6c81..f2e835b 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -6,7 +6,6 @@ SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )" # Change to the script directory cd "$SCRIPT_DIR" -kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.18.2/cert-manager.yaml kubectl apply -f helm/flux.yaml sleep 5 kubectl apply -f helm/kyverno.yaml diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index 79ce4f2..303626c 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -6,6 +6,9 @@ }: let cfg = config.greg.kubernetes; + cert-manager = pkgs.fetchurl { + url = "https://github.com/cert-manager/cert-manager/releases/download/v1.18.2/cert-manager.yaml"; + }; in { options.greg = { @@ -82,6 +85,7 @@ in "--tls-san ${config.networking.hostName}.shire-zebra.ts.net" ]; manifests = { + cert-manager.source = cert-manager; node-annotations.content = ../../manifests/nodes.yaml; }; role = if cfg.agentOnly then "agent" else "server"; From 3cf32090d6a937699e9db3ef8c303095a1f1f50c Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 5 Sep 2025 13:39:10 -0500 Subject: [PATCH 093/124] Move flux to NixOS and add URL hashes --- manifests/apply.sh | 2 - manifests/helm/flux.yaml | 12810 --------------------------------- modules/nixos/kubernetes.nix | 6 + 3 files changed, 6 insertions(+), 12812 deletions(-) delete mode 100644 manifests/helm/flux.yaml diff --git a/manifests/apply.sh b/manifests/apply.sh index f2e835b..7ffe584 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -6,8 +6,6 @@ SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )" # Change to the script directory cd "$SCRIPT_DIR" -kubectl apply -f helm/flux.yaml -sleep 5 kubectl apply -f helm/kyverno.yaml sleep 15 kubectl apply -k helm diff --git a/manifests/helm/flux.yaml b/manifests/helm/flux.yaml deleted file mode 100644 index ceba2d2..0000000 --- a/manifests/helm/flux.yaml +++ /dev/null @@ -1,12810 +0,0 @@ ---- -# This manifest was generated by flux. DO NOT EDIT. -# Flux Version: v2.5.1 -# Components: source-controller,kustomize-controller,helm-controller,notification-controller -apiVersion: v1 -kind: Namespace -metadata: - labels: - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - pod-security.kubernetes.io/warn: restricted - pod-security.kubernetes.io/warn-version: latest - name: flux-system ---- -apiVersion: v1 -kind: ResourceQuota -metadata: - labels: - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: critical-pods-flux-system - namespace: flux-system -spec: - hard: - pods: "1000" - scopeSelector: - matchExpressions: - - operator: In - scopeName: PriorityClass - values: - - system-node-critical - - system-cluster-critical ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - labels: - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: crd-controller-flux-system -rules: - - apiGroups: - - source.toolkit.fluxcd.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - kustomize.toolkit.fluxcd.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - helm.toolkit.fluxcd.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - notification.toolkit.fluxcd.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - image.toolkit.fluxcd.io - resources: - - "*" - verbs: - - "*" - - apiGroups: - - "" - resources: - - namespaces - - secrets - - configmaps - - serviceaccounts - verbs: - - get - - list - - watch - - apiGroups: - - "" - resources: - - events - verbs: - - create - - patch - - apiGroups: - - "" - resources: - - configmaps - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - apiGroups: - - "" - resources: - - configmaps/status - verbs: - - get - - update - - patch - - apiGroups: - - coordination.k8s.io - resources: - - leases - verbs: - - get - - list - - watch - - create - - update - - patch - - delete - - nonResourceURLs: - - /livez/ping - verbs: - - head ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - labels: - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - rbac.authorization.k8s.io/aggregate-to-admin: "true" - rbac.authorization.k8s.io/aggregate-to-edit: "true" - name: flux-edit-flux-system -rules: - - apiGroups: - - notification.toolkit.fluxcd.io - - source.toolkit.fluxcd.io - - helm.toolkit.fluxcd.io - - image.toolkit.fluxcd.io - - kustomize.toolkit.fluxcd.io - resources: - - "*" - verbs: - - create - - delete - - deletecollection - - patch - - update ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRole -metadata: - labels: - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - rbac.authorization.k8s.io/aggregate-to-admin: "true" - rbac.authorization.k8s.io/aggregate-to-edit: "true" - rbac.authorization.k8s.io/aggregate-to-view: "true" - name: flux-view-flux-system -rules: - - apiGroups: - - notification.toolkit.fluxcd.io - - source.toolkit.fluxcd.io - - helm.toolkit.fluxcd.io - - image.toolkit.fluxcd.io - - kustomize.toolkit.fluxcd.io - resources: - - "*" - verbs: - - get - - list - - watch ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - labels: - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: cluster-reconciler-flux-system -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: cluster-admin -subjects: - - kind: ServiceAccount - name: kustomize-controller - namespace: flux-system - - kind: ServiceAccount - name: helm-controller - namespace: flux-system ---- -apiVersion: rbac.authorization.k8s.io/v1 -kind: ClusterRoleBinding -metadata: - labels: - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: crd-controller-flux-system -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: ClusterRole - name: crd-controller-flux-system -subjects: - - kind: ServiceAccount - name: kustomize-controller - namespace: flux-system - - kind: ServiceAccount - name: helm-controller - namespace: flux-system - - kind: ServiceAccount - name: source-controller - namespace: flux-system - - kind: ServiceAccount - name: notification-controller - namespace: flux-system - - kind: ServiceAccount - name: image-reflector-controller - namespace: flux-system - - kind: ServiceAccount - name: image-automation-controller - namespace: flux-system ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: source-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: buckets.source.toolkit.fluxcd.io -spec: - group: source.toolkit.fluxcd.io - names: - kind: Bucket - listKind: BucketList - plural: buckets - singular: bucket - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.endpoint - name: Endpoint - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - name: v1 - schema: - openAPIV3Schema: - description: Bucket is the Schema for the buckets API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: |- - BucketSpec specifies the required configuration to produce an Artifact for - an object storage bucket. - properties: - bucketName: - description: BucketName is the name of the object storage bucket. - type: string - certSecretRef: - description: |- - CertSecretRef can be given the name of a Secret containing - either or both of - - - a PEM-encoded client certificate (`tls.crt`) and private - key (`tls.key`); - - a PEM-encoded CA certificate (`ca.crt`) - - and whichever are supplied, will be used for connecting to the - bucket. The client cert and key are useful if you are - authenticating with a certificate; the CA cert is useful if - you are using a self-signed server certificate. The Secret must - be of type `Opaque` or `kubernetes.io/tls`. - - This field is only supported for the `generic` provider. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - endpoint: - description: - Endpoint is the object storage address the BucketName - is located at. - type: string - ignore: - description: |- - Ignore overrides the set of excluded patterns in the .sourceignore format - (which is the same as .gitignore). If not provided, a default will be used, - consult the documentation for your version to find out what those are. - type: string - insecure: - description: Insecure allows connecting to a non-TLS HTTP Endpoint. - type: boolean - interval: - description: |- - Interval at which the Bucket Endpoint is checked for updates. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - prefix: - description: - Prefix to use for server-side filtering of files in the - Bucket. - type: string - provider: - default: generic - description: |- - Provider of the object storage bucket. - Defaults to 'generic', which expects an S3 (API) compatible object - storage. - enum: - - generic - - aws - - gcp - - azure - type: string - proxySecretRef: - description: |- - ProxySecretRef specifies the Secret containing the proxy configuration - to use while communicating with the Bucket server. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - region: - description: - Region of the Endpoint where the BucketName is located - in. - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing authentication credentials - for the Bucket. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - sts: - description: |- - STS specifies the required configuration to use a Security Token - Service for fetching temporary credentials to authenticate in a - Bucket provider. - - This field is only supported for the `aws` and `generic` providers. - properties: - certSecretRef: - description: |- - CertSecretRef can be given the name of a Secret containing - either or both of - - - a PEM-encoded client certificate (`tls.crt`) and private - key (`tls.key`); - - a PEM-encoded CA certificate (`ca.crt`) - - and whichever are supplied, will be used for connecting to the - STS endpoint. The client cert and key are useful if you are - authenticating with a certificate; the CA cert is useful if - you are using a self-signed server certificate. The Secret must - be of type `Opaque` or `kubernetes.io/tls`. - - This field is only supported for the `ldap` provider. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - endpoint: - description: |- - Endpoint is the HTTP/S endpoint of the Security Token Service from - where temporary credentials will be fetched. - pattern: ^(http|https)://.*$ - type: string - provider: - description: Provider of the Security Token Service. - enum: - - aws - - ldap - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing authentication credentials - for the STS endpoint. This Secret must contain the fields `username` - and `password` and is supported only for the `ldap` provider. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - endpoint - - provider - type: object - suspend: - description: |- - Suspend tells the controller to suspend the reconciliation of this - Bucket. - type: boolean - timeout: - default: 60s - description: Timeout for fetch operations, defaults to 60s. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - required: - - bucketName - - endpoint - - interval - type: object - x-kubernetes-validations: - - message: - STS configuration is only supported for the 'aws' and 'generic' - Bucket providers - rule: self.provider == 'aws' || self.provider == 'generic' || !has(self.sts) - - message: - "'aws' is the only supported STS provider for the 'aws' - Bucket provider" - rule: - self.provider != 'aws' || !has(self.sts) || self.sts.provider - == 'aws' - - message: - "'ldap' is the only supported STS provider for the 'generic' - Bucket provider" - rule: - self.provider != 'generic' || !has(self.sts) || self.sts.provider - == 'ldap' - - message: spec.sts.secretRef is not required for the 'aws' STS provider - rule: "!has(self.sts) || self.sts.provider != 'aws' || !has(self.sts.secretRef)" - - message: spec.sts.certSecretRef is not required for the 'aws' STS provider - rule: "!has(self.sts) || self.sts.provider != 'aws' || !has(self.sts.certSecretRef)" - status: - default: - observedGeneration: -1 - description: BucketStatus records the observed state of a Bucket. - properties: - artifact: - description: Artifact represents the last successful Bucket reconciliation. - properties: - digest: - description: Digest is the digest of the file in the form of ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: Metadata holds upstream information such as OCI annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - conditions: - description: Conditions holds the conditions for the Bucket. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: - ObservedGeneration is the last observed generation of - the Bucket object. - format: int64 - type: integer - observedIgnore: - description: |- - ObservedIgnore is the observed exclusion patterns used for constructing - the source artifact. - type: string - url: - description: |- - URL is the dynamic fetch link for the latest Artifact. - It is provided on a "best effort" basis, and using the precise - BucketStatus.Artifact data is recommended. - type: string - type: object - type: object - served: true - storage: true - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .spec.endpoint - name: Endpoint - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - deprecated: true - deprecationWarning: v1beta1 Bucket is deprecated, upgrade to v1 - name: v1beta1 - schema: - openAPIV3Schema: - description: Bucket is the Schema for the buckets API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: - BucketSpec defines the desired state of an S3 compatible - bucket - properties: - accessFrom: - description: - AccessFrom defines an Access Control List for allowing - cross-namespace references to this object. - properties: - namespaceSelectors: - description: |- - NamespaceSelectors is the list of namespace selectors to which this ACL applies. - Items in this list are evaluated using a logical OR operation. - items: - description: |- - NamespaceSelector selects the namespaces to which this ACL applies. - An empty map of MatchLabels matches all namespaces in a cluster. - properties: - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - type: array - required: - - namespaceSelectors - type: object - bucketName: - description: The bucket name. - type: string - endpoint: - description: The bucket endpoint address. - type: string - ignore: - description: |- - Ignore overrides the set of excluded patterns in the .sourceignore format - (which is the same as .gitignore). If not provided, a default will be used, - consult the documentation for your version to find out what those are. - type: string - insecure: - description: Insecure allows connecting to a non-TLS S3 HTTP endpoint. - type: boolean - interval: - description: The interval at which to check for bucket updates. - type: string - provider: - default: generic - description: The S3 compatible storage provider name, default ('generic'). - enum: - - generic - - aws - - gcp - type: string - region: - description: The bucket region. - type: string - secretRef: - description: |- - The name of the secret containing authentication credentials - for the Bucket. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: - This flag tells the controller to suspend the reconciliation - of this source. - type: boolean - timeout: - default: 60s - description: The timeout for download operations, defaults to 60s. - type: string - required: - - bucketName - - endpoint - - interval - type: object - status: - default: - observedGeneration: -1 - description: BucketStatus defines the observed state of a bucket - properties: - artifact: - description: - Artifact represents the output of the last successful - Bucket sync. - properties: - checksum: - description: Checksum is the SHA256 checksum of the artifact. - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of this - artifact. - format: date-time - type: string - path: - description: Path is the relative file path of this artifact. - type: string - revision: - description: |- - Revision is a human readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm index timestamp, a Helm - chart version, etc. - type: string - url: - description: URL is the HTTP address of this artifact. - type: string - required: - - lastUpdateTime - - path - - url - type: object - conditions: - description: Conditions holds the conditions for the Bucket. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - url: - description: - URL is the download link for the artifact output of the - last Bucket sync. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .spec.endpoint - name: Endpoint - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta2 Bucket is deprecated, upgrade to v1 - name: v1beta2 - schema: - openAPIV3Schema: - description: Bucket is the Schema for the buckets API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: |- - BucketSpec specifies the required configuration to produce an Artifact for - an object storage bucket. - properties: - accessFrom: - description: |- - AccessFrom specifies an Access Control List for allowing cross-namespace - references to this object. - NOTE: Not implemented, provisional as of https://github.com/fluxcd/flux2/pull/2092 - properties: - namespaceSelectors: - description: |- - NamespaceSelectors is the list of namespace selectors to which this ACL applies. - Items in this list are evaluated using a logical OR operation. - items: - description: |- - NamespaceSelector selects the namespaces to which this ACL applies. - An empty map of MatchLabels matches all namespaces in a cluster. - properties: - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - type: array - required: - - namespaceSelectors - type: object - bucketName: - description: BucketName is the name of the object storage bucket. - type: string - certSecretRef: - description: |- - CertSecretRef can be given the name of a Secret containing - either or both of - - - a PEM-encoded client certificate (`tls.crt`) and private - key (`tls.key`); - - a PEM-encoded CA certificate (`ca.crt`) - - and whichever are supplied, will be used for connecting to the - bucket. The client cert and key are useful if you are - authenticating with a certificate; the CA cert is useful if - you are using a self-signed server certificate. The Secret must - be of type `Opaque` or `kubernetes.io/tls`. - - This field is only supported for the `generic` provider. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - endpoint: - description: - Endpoint is the object storage address the BucketName - is located at. - type: string - ignore: - description: |- - Ignore overrides the set of excluded patterns in the .sourceignore format - (which is the same as .gitignore). If not provided, a default will be used, - consult the documentation for your version to find out what those are. - type: string - insecure: - description: Insecure allows connecting to a non-TLS HTTP Endpoint. - type: boolean - interval: - description: |- - Interval at which the Bucket Endpoint is checked for updates. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - prefix: - description: - Prefix to use for server-side filtering of files in the - Bucket. - type: string - provider: - default: generic - description: |- - Provider of the object storage bucket. - Defaults to 'generic', which expects an S3 (API) compatible object - storage. - enum: - - generic - - aws - - gcp - - azure - type: string - proxySecretRef: - description: |- - ProxySecretRef specifies the Secret containing the proxy configuration - to use while communicating with the Bucket server. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - region: - description: - Region of the Endpoint where the BucketName is located - in. - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing authentication credentials - for the Bucket. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - sts: - description: |- - STS specifies the required configuration to use a Security Token - Service for fetching temporary credentials to authenticate in a - Bucket provider. - - This field is only supported for the `aws` and `generic` providers. - properties: - certSecretRef: - description: |- - CertSecretRef can be given the name of a Secret containing - either or both of - - - a PEM-encoded client certificate (`tls.crt`) and private - key (`tls.key`); - - a PEM-encoded CA certificate (`ca.crt`) - - and whichever are supplied, will be used for connecting to the - STS endpoint. The client cert and key are useful if you are - authenticating with a certificate; the CA cert is useful if - you are using a self-signed server certificate. The Secret must - be of type `Opaque` or `kubernetes.io/tls`. - - This field is only supported for the `ldap` provider. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - endpoint: - description: |- - Endpoint is the HTTP/S endpoint of the Security Token Service from - where temporary credentials will be fetched. - pattern: ^(http|https)://.*$ - type: string - provider: - description: Provider of the Security Token Service. - enum: - - aws - - ldap - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing authentication credentials - for the STS endpoint. This Secret must contain the fields `username` - and `password` and is supported only for the `ldap` provider. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - endpoint - - provider - type: object - suspend: - description: |- - Suspend tells the controller to suspend the reconciliation of this - Bucket. - type: boolean - timeout: - default: 60s - description: Timeout for fetch operations, defaults to 60s. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - required: - - bucketName - - endpoint - - interval - type: object - x-kubernetes-validations: - - message: - STS configuration is only supported for the 'aws' and 'generic' - Bucket providers - rule: self.provider == 'aws' || self.provider == 'generic' || !has(self.sts) - - message: - "'aws' is the only supported STS provider for the 'aws' - Bucket provider" - rule: - self.provider != 'aws' || !has(self.sts) || self.sts.provider - == 'aws' - - message: - "'ldap' is the only supported STS provider for the 'generic' - Bucket provider" - rule: - self.provider != 'generic' || !has(self.sts) || self.sts.provider - == 'ldap' - - message: spec.sts.secretRef is not required for the 'aws' STS provider - rule: "!has(self.sts) || self.sts.provider != 'aws' || !has(self.sts.secretRef)" - - message: spec.sts.certSecretRef is not required for the 'aws' STS provider - rule: "!has(self.sts) || self.sts.provider != 'aws' || !has(self.sts.certSecretRef)" - status: - default: - observedGeneration: -1 - description: BucketStatus records the observed state of a Bucket. - properties: - artifact: - description: Artifact represents the last successful Bucket reconciliation. - properties: - digest: - description: Digest is the digest of the file in the form of ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: Metadata holds upstream information such as OCI annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - conditions: - description: Conditions holds the conditions for the Bucket. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: - ObservedGeneration is the last observed generation of - the Bucket object. - format: int64 - type: integer - observedIgnore: - description: |- - ObservedIgnore is the observed exclusion patterns used for constructing - the source artifact. - type: string - url: - description: |- - URL is the dynamic fetch link for the latest Artifact. - It is provided on a "best effort" basis, and using the precise - BucketStatus.Artifact data is recommended. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: source-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: gitrepositories.source.toolkit.fluxcd.io -spec: - group: source.toolkit.fluxcd.io - names: - kind: GitRepository - listKind: GitRepositoryList - plural: gitrepositories - shortNames: - - gitrepo - singular: gitrepository - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.url - name: URL - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - name: v1 - schema: - openAPIV3Schema: - description: GitRepository is the Schema for the gitrepositories API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: |- - GitRepositorySpec specifies the required configuration to produce an - Artifact for a Git repository. - properties: - ignore: - description: |- - Ignore overrides the set of excluded patterns in the .sourceignore format - (which is the same as .gitignore). If not provided, a default will be used, - consult the documentation for your version to find out what those are. - type: string - include: - description: |- - Include specifies a list of GitRepository resources which Artifacts - should be included in the Artifact produced for this GitRepository. - items: - description: |- - GitRepositoryInclude specifies a local reference to a GitRepository which - Artifact (sub-)contents must be included, and where they should be placed. - properties: - fromPath: - description: |- - FromPath specifies the path to copy contents from, defaults to the root - of the Artifact. - type: string - repository: - description: |- - GitRepositoryRef specifies the GitRepository which Artifact contents - must be included. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - toPath: - description: |- - ToPath specifies the path to copy contents to, defaults to the name of - the GitRepositoryRef. - type: string - required: - - repository - type: object - type: array - interval: - description: |- - Interval at which the GitRepository URL is checked for updates. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - provider: - description: |- - Provider used for authentication, can be 'azure', 'github', 'generic'. - When not specified, defaults to 'generic'. - enum: - - generic - - azure - - github - type: string - proxySecretRef: - description: |- - ProxySecretRef specifies the Secret containing the proxy configuration - to use while communicating with the Git server. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - recurseSubmodules: - description: |- - RecurseSubmodules enables the initialization of all submodules within - the GitRepository as cloned from the URL, using their default settings. - type: boolean - ref: - description: |- - Reference specifies the Git reference to resolve and monitor for - changes, defaults to the 'master' branch. - properties: - branch: - description: - Branch to check out, defaults to 'master' if no other - field is defined. - type: string - commit: - description: |- - Commit SHA to check out, takes precedence over all reference fields. - - This can be combined with Branch to shallow clone the branch, in which - the commit is expected to exist. - type: string - name: - description: |- - Name of the reference to check out; takes precedence over Branch, Tag and SemVer. - - It must be a valid Git reference: https://git-scm.com/docs/git-check-ref-format#_description - Examples: "refs/heads/main", "refs/tags/v0.1.0", "refs/pull/420/head", "refs/merge-requests/1/head" - type: string - semver: - description: - SemVer tag expression to check out, takes precedence - over Tag. - type: string - tag: - description: Tag to check out, takes precedence over Branch. - type: string - type: object - secretRef: - description: |- - SecretRef specifies the Secret containing authentication credentials for - the GitRepository. - For HTTPS repositories the Secret must contain 'username' and 'password' - fields for basic auth or 'bearerToken' field for token auth. - For SSH repositories the Secret must contain 'identity' - and 'known_hosts' fields. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend the reconciliation of this - GitRepository. - type: boolean - timeout: - default: 60s - description: - Timeout for Git operations like cloning, defaults to - 60s. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - url: - description: - URL specifies the Git repository URL, it can be an HTTP/S - or SSH address. - pattern: ^(http|https|ssh)://.*$ - type: string - verify: - description: |- - Verification specifies the configuration to verify the Git commit - signature(s). - properties: - mode: - default: HEAD - description: |- - Mode specifies which Git object(s) should be verified. - - The variants "head" and "HEAD" both imply the same thing, i.e. verify - the commit that the HEAD of the Git repository points to. The variant - "head" solely exists to ensure backwards compatibility. - enum: - - head - - HEAD - - Tag - - TagAndHEAD - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing the public keys of trusted Git - authors. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - secretRef - type: object - required: - - interval - - url - type: object - status: - default: - observedGeneration: -1 - description: GitRepositoryStatus records the observed state of a Git repository. - properties: - artifact: - description: - Artifact represents the last successful GitRepository - reconciliation. - properties: - digest: - description: Digest is the digest of the file in the form of ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: Metadata holds upstream information such as OCI annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - conditions: - description: Conditions holds the conditions for the GitRepository. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - includedArtifacts: - description: |- - IncludedArtifacts contains a list of the last successfully included - Artifacts as instructed by GitRepositorySpec.Include. - items: - description: Artifact represents the output of a Source reconciliation. - properties: - digest: - description: - Digest is the digest of the file in the form of - ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: - Metadata holds upstream information such as OCI - annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: |- - ObservedGeneration is the last observed generation of the GitRepository - object. - format: int64 - type: integer - observedIgnore: - description: |- - ObservedIgnore is the observed exclusion patterns used for constructing - the source artifact. - type: string - observedInclude: - description: |- - ObservedInclude is the observed list of GitRepository resources used to - produce the current Artifact. - items: - description: |- - GitRepositoryInclude specifies a local reference to a GitRepository which - Artifact (sub-)contents must be included, and where they should be placed. - properties: - fromPath: - description: |- - FromPath specifies the path to copy contents from, defaults to the root - of the Artifact. - type: string - repository: - description: |- - GitRepositoryRef specifies the GitRepository which Artifact contents - must be included. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - toPath: - description: |- - ToPath specifies the path to copy contents to, defaults to the name of - the GitRepositoryRef. - type: string - required: - - repository - type: object - type: array - observedRecurseSubmodules: - description: |- - ObservedRecurseSubmodules is the observed resource submodules - configuration used to produce the current Artifact. - type: boolean - sourceVerificationMode: - description: |- - SourceVerificationMode is the last used verification mode indicating - which Git object(s) have been verified. - type: string - type: object - type: object - served: true - storage: true - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .spec.url - name: URL - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - deprecated: true - deprecationWarning: v1beta1 GitRepository is deprecated, upgrade to v1 - name: v1beta1 - schema: - openAPIV3Schema: - description: GitRepository is the Schema for the gitrepositories API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: GitRepositorySpec defines the desired state of a Git repository. - properties: - accessFrom: - description: - AccessFrom defines an Access Control List for allowing - cross-namespace references to this object. - properties: - namespaceSelectors: - description: |- - NamespaceSelectors is the list of namespace selectors to which this ACL applies. - Items in this list are evaluated using a logical OR operation. - items: - description: |- - NamespaceSelector selects the namespaces to which this ACL applies. - An empty map of MatchLabels matches all namespaces in a cluster. - properties: - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - type: array - required: - - namespaceSelectors - type: object - gitImplementation: - default: go-git - description: |- - Determines which git client library to use. - Defaults to go-git, valid values are ('go-git', 'libgit2'). - enum: - - go-git - - libgit2 - type: string - ignore: - description: |- - Ignore overrides the set of excluded patterns in the .sourceignore format - (which is the same as .gitignore). If not provided, a default will be used, - consult the documentation for your version to find out what those are. - type: string - include: - description: Extra git repositories to map into the repository - items: - description: - GitRepositoryInclude defines a source with a from and - to path. - properties: - fromPath: - description: - The path to copy contents from, defaults to the - root directory. - type: string - repository: - description: Reference to a GitRepository to include. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - toPath: - description: - The path to copy contents to, defaults to the name - of the source ref. - type: string - required: - - repository - type: object - type: array - interval: - description: The interval at which to check for repository updates. - type: string - recurseSubmodules: - description: |- - When enabled, after the clone is created, initializes all submodules within, - using their default settings. - This option is available only when using the 'go-git' GitImplementation. - type: boolean - ref: - description: |- - The Git reference to checkout and monitor for changes, defaults to - master branch. - properties: - branch: - description: The Git branch to checkout, defaults to master. - type: string - commit: - description: - The Git commit SHA to checkout, if specified Tag - filters will be ignored. - type: string - semver: - description: - The Git tag semver expression, takes precedence over - Tag. - type: string - tag: - description: The Git tag to checkout, takes precedence over Branch. - type: string - type: object - secretRef: - description: |- - The secret name containing the Git credentials. - For HTTPS repositories the secret must contain username and password - fields. - For SSH repositories the secret must contain identity and known_hosts - fields. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: - This flag tells the controller to suspend the reconciliation - of this source. - type: boolean - timeout: - default: 60s - description: - The timeout for remote Git operations like cloning, defaults - to 60s. - type: string - url: - description: The repository URL, can be a HTTP/S or SSH address. - pattern: ^(http|https|ssh)://.*$ - type: string - verify: - description: - Verify OpenPGP signature for the Git commit HEAD points - to. - properties: - mode: - description: - Mode describes what git object should be verified, - currently ('head'). - enum: - - head - type: string - secretRef: - description: - The secret name containing the public keys of all - trusted Git authors. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - mode - type: object - required: - - interval - - url - type: object - status: - default: - observedGeneration: -1 - description: GitRepositoryStatus defines the observed state of a Git repository. - properties: - artifact: - description: - Artifact represents the output of the last successful - repository sync. - properties: - checksum: - description: Checksum is the SHA256 checksum of the artifact. - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of this - artifact. - format: date-time - type: string - path: - description: Path is the relative file path of this artifact. - type: string - revision: - description: |- - Revision is a human readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm index timestamp, a Helm - chart version, etc. - type: string - url: - description: URL is the HTTP address of this artifact. - type: string - required: - - lastUpdateTime - - path - - url - type: object - conditions: - description: Conditions holds the conditions for the GitRepository. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - includedArtifacts: - description: - IncludedArtifacts represents the included artifacts from - the last successful repository sync. - items: - description: Artifact represents the output of a source synchronisation. - properties: - checksum: - description: Checksum is the SHA256 checksum of the artifact. - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of this - artifact. - format: date-time - type: string - path: - description: Path is the relative file path of this artifact. - type: string - revision: - description: |- - Revision is a human readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm index timestamp, a Helm - chart version, etc. - type: string - url: - description: URL is the HTTP address of this artifact. - type: string - required: - - lastUpdateTime - - path - - url - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - url: - description: |- - URL is the download link for the artifact output of the last repository - sync. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .spec.url - name: URL - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta2 GitRepository is deprecated, upgrade to v1 - name: v1beta2 - schema: - openAPIV3Schema: - description: GitRepository is the Schema for the gitrepositories API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: |- - GitRepositorySpec specifies the required configuration to produce an - Artifact for a Git repository. - properties: - accessFrom: - description: |- - AccessFrom specifies an Access Control List for allowing cross-namespace - references to this object. - NOTE: Not implemented, provisional as of https://github.com/fluxcd/flux2/pull/2092 - properties: - namespaceSelectors: - description: |- - NamespaceSelectors is the list of namespace selectors to which this ACL applies. - Items in this list are evaluated using a logical OR operation. - items: - description: |- - NamespaceSelector selects the namespaces to which this ACL applies. - An empty map of MatchLabels matches all namespaces in a cluster. - properties: - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - type: array - required: - - namespaceSelectors - type: object - gitImplementation: - default: go-git - description: |- - GitImplementation specifies which Git client library implementation to - use. Defaults to 'go-git', valid values are ('go-git', 'libgit2'). - Deprecated: gitImplementation is deprecated now that 'go-git' is the - only supported implementation. - enum: - - go-git - - libgit2 - type: string - ignore: - description: |- - Ignore overrides the set of excluded patterns in the .sourceignore format - (which is the same as .gitignore). If not provided, a default will be used, - consult the documentation for your version to find out what those are. - type: string - include: - description: |- - Include specifies a list of GitRepository resources which Artifacts - should be included in the Artifact produced for this GitRepository. - items: - description: |- - GitRepositoryInclude specifies a local reference to a GitRepository which - Artifact (sub-)contents must be included, and where they should be placed. - properties: - fromPath: - description: |- - FromPath specifies the path to copy contents from, defaults to the root - of the Artifact. - type: string - repository: - description: |- - GitRepositoryRef specifies the GitRepository which Artifact contents - must be included. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - toPath: - description: |- - ToPath specifies the path to copy contents to, defaults to the name of - the GitRepositoryRef. - type: string - required: - - repository - type: object - type: array - interval: - description: Interval at which to check the GitRepository for updates. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - recurseSubmodules: - description: |- - RecurseSubmodules enables the initialization of all submodules within - the GitRepository as cloned from the URL, using their default settings. - type: boolean - ref: - description: |- - Reference specifies the Git reference to resolve and monitor for - changes, defaults to the 'master' branch. - properties: - branch: - description: - Branch to check out, defaults to 'master' if no other - field is defined. - type: string - commit: - description: |- - Commit SHA to check out, takes precedence over all reference fields. - - This can be combined with Branch to shallow clone the branch, in which - the commit is expected to exist. - type: string - name: - description: |- - Name of the reference to check out; takes precedence over Branch, Tag and SemVer. - - It must be a valid Git reference: https://git-scm.com/docs/git-check-ref-format#_description - Examples: "refs/heads/main", "refs/tags/v0.1.0", "refs/pull/420/head", "refs/merge-requests/1/head" - type: string - semver: - description: - SemVer tag expression to check out, takes precedence - over Tag. - type: string - tag: - description: Tag to check out, takes precedence over Branch. - type: string - type: object - secretRef: - description: |- - SecretRef specifies the Secret containing authentication credentials for - the GitRepository. - For HTTPS repositories the Secret must contain 'username' and 'password' - fields for basic auth or 'bearerToken' field for token auth. - For SSH repositories the Secret must contain 'identity' - and 'known_hosts' fields. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend the reconciliation of this - GitRepository. - type: boolean - timeout: - default: 60s - description: - Timeout for Git operations like cloning, defaults to - 60s. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - url: - description: - URL specifies the Git repository URL, it can be an HTTP/S - or SSH address. - pattern: ^(http|https|ssh)://.*$ - type: string - verify: - description: |- - Verification specifies the configuration to verify the Git commit - signature(s). - properties: - mode: - description: - Mode specifies what Git object should be verified, - currently ('head'). - enum: - - head - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing the public keys of trusted Git - authors. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - mode - - secretRef - type: object - required: - - interval - - url - type: object - status: - default: - observedGeneration: -1 - description: GitRepositoryStatus records the observed state of a Git repository. - properties: - artifact: - description: - Artifact represents the last successful GitRepository - reconciliation. - properties: - digest: - description: Digest is the digest of the file in the form of ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: Metadata holds upstream information such as OCI annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - conditions: - description: Conditions holds the conditions for the GitRepository. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - contentConfigChecksum: - description: |- - ContentConfigChecksum is a checksum of all the configurations related to - the content of the source artifact: - - .spec.ignore - - .spec.recurseSubmodules - - .spec.included and the checksum of the included artifacts - observed in .status.observedGeneration version of the object. This can - be used to determine if the content of the included repository has - changed. - It has the format of `:`, for example: `sha256:`. - - Deprecated: Replaced with explicit fields for observed artifact content - config in the status. - type: string - includedArtifacts: - description: |- - IncludedArtifacts contains a list of the last successfully included - Artifacts as instructed by GitRepositorySpec.Include. - items: - description: Artifact represents the output of a Source reconciliation. - properties: - digest: - description: - Digest is the digest of the file in the form of - ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: - Metadata holds upstream information such as OCI - annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: |- - ObservedGeneration is the last observed generation of the GitRepository - object. - format: int64 - type: integer - observedIgnore: - description: |- - ObservedIgnore is the observed exclusion patterns used for constructing - the source artifact. - type: string - observedInclude: - description: |- - ObservedInclude is the observed list of GitRepository resources used to - to produce the current Artifact. - items: - description: |- - GitRepositoryInclude specifies a local reference to a GitRepository which - Artifact (sub-)contents must be included, and where they should be placed. - properties: - fromPath: - description: |- - FromPath specifies the path to copy contents from, defaults to the root - of the Artifact. - type: string - repository: - description: |- - GitRepositoryRef specifies the GitRepository which Artifact contents - must be included. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - toPath: - description: |- - ToPath specifies the path to copy contents to, defaults to the name of - the GitRepositoryRef. - type: string - required: - - repository - type: object - type: array - observedRecurseSubmodules: - description: |- - ObservedRecurseSubmodules is the observed resource submodules - configuration used to produce the current Artifact. - type: boolean - url: - description: |- - URL is the dynamic fetch link for the latest Artifact. - It is provided on a "best effort" basis, and using the precise - GitRepositoryStatus.Artifact data is recommended. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: source-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: helmcharts.source.toolkit.fluxcd.io -spec: - group: source.toolkit.fluxcd.io - names: - kind: HelmChart - listKind: HelmChartList - plural: helmcharts - shortNames: - - hc - singular: helmchart - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.chart - name: Chart - type: string - - jsonPath: .spec.version - name: Version - type: string - - jsonPath: .spec.sourceRef.kind - name: Source Kind - type: string - - jsonPath: .spec.sourceRef.name - name: Source Name - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - name: v1 - schema: - openAPIV3Schema: - description: HelmChart is the Schema for the helmcharts API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: HelmChartSpec specifies the desired state of a Helm chart. - properties: - chart: - description: |- - Chart is the name or path the Helm chart is available at in the - SourceRef. - type: string - ignoreMissingValuesFiles: - description: |- - IgnoreMissingValuesFiles controls whether to silently ignore missing values - files rather than failing. - type: boolean - interval: - description: |- - Interval at which the HelmChart SourceRef is checked for updates. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - reconcileStrategy: - default: ChartVersion - description: |- - ReconcileStrategy determines what enables the creation of a new artifact. - Valid values are ('ChartVersion', 'Revision'). - See the documentation of the values for an explanation on their behavior. - Defaults to ChartVersion when omitted. - enum: - - ChartVersion - - Revision - type: string - sourceRef: - description: - SourceRef is the reference to the Source the chart is - available at. - properties: - apiVersion: - description: APIVersion of the referent. - type: string - kind: - description: |- - Kind of the referent, valid values are ('HelmRepository', 'GitRepository', - 'Bucket'). - enum: - - HelmRepository - - GitRepository - - Bucket - type: string - name: - description: Name of the referent. - type: string - required: - - kind - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend the reconciliation of this - source. - type: boolean - valuesFiles: - description: |- - ValuesFiles is an alternative list of values files to use as the chart - values (values.yaml is not included by default), expected to be a - relative path in the SourceRef. - Values files are merged in the order of this list with the last file - overriding the first. Ignored when omitted. - items: - type: string - type: array - verify: - description: |- - Verify contains the secret name containing the trusted public keys - used to verify the signature and specifies which provider to use to check - whether OCI image is authentic. - This field is only supported when using HelmRepository source with spec.type 'oci'. - Chart dependencies, which are not bundled in the umbrella chart artifact, are not verified. - properties: - matchOIDCIdentity: - description: |- - MatchOIDCIdentity specifies the identity matching criteria to use - while verifying an OCI artifact which was signed using Cosign keyless - signing. The artifact's identity is deemed to be verified if any of the - specified matchers match against the identity. - items: - description: |- - OIDCIdentityMatch specifies options for verifying the certificate identity, - i.e. the issuer and the subject of the certificate. - properties: - issuer: - description: |- - Issuer specifies the regex pattern to match against to verify - the OIDC issuer in the Fulcio certificate. The pattern must be a - valid Go regular expression. - type: string - subject: - description: |- - Subject specifies the regex pattern to match against to verify - the identity subject in the Fulcio certificate. The pattern must - be a valid Go regular expression. - type: string - required: - - issuer - - subject - type: object - type: array - provider: - default: cosign - description: - Provider specifies the technology used to sign the - OCI Artifact. - enum: - - cosign - - notation - type: string - secretRef: - description: |- - SecretRef specifies the Kubernetes Secret containing the - trusted public keys. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - provider - type: object - version: - default: "*" - description: |- - Version is the chart version semver expression, ignored for charts from - GitRepository and Bucket sources. Defaults to latest when omitted. - type: string - required: - - chart - - interval - - sourceRef - type: object - status: - default: - observedGeneration: -1 - description: HelmChartStatus records the observed state of the HelmChart. - properties: - artifact: - description: - Artifact represents the output of the last successful - reconciliation. - properties: - digest: - description: Digest is the digest of the file in the form of ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: Metadata holds upstream information such as OCI annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - conditions: - description: Conditions holds the conditions for the HelmChart. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedChartName: - description: |- - ObservedChartName is the last observed chart name as specified by the - resolved chart reference. - type: string - observedGeneration: - description: |- - ObservedGeneration is the last observed generation of the HelmChart - object. - format: int64 - type: integer - observedSourceArtifactRevision: - description: |- - ObservedSourceArtifactRevision is the last observed Artifact.Revision - of the HelmChartSpec.SourceRef. - type: string - observedValuesFiles: - description: |- - ObservedValuesFiles are the observed value files of the last successful - reconciliation. - It matches the chart in the last successfully reconciled artifact. - items: - type: string - type: array - url: - description: |- - URL is the dynamic fetch link for the latest Artifact. - It is provided on a "best effort" basis, and using the precise - BucketStatus.Artifact data is recommended. - type: string - type: object - type: object - served: true - storage: true - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .spec.chart - name: Chart - type: string - - jsonPath: .spec.version - name: Version - type: string - - jsonPath: .spec.sourceRef.kind - name: Source Kind - type: string - - jsonPath: .spec.sourceRef.name - name: Source Name - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - deprecated: true - deprecationWarning: v1beta1 HelmChart is deprecated, upgrade to v1 - name: v1beta1 - schema: - openAPIV3Schema: - description: HelmChart is the Schema for the helmcharts API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: HelmChartSpec defines the desired state of a Helm chart. - properties: - accessFrom: - description: - AccessFrom defines an Access Control List for allowing - cross-namespace references to this object. - properties: - namespaceSelectors: - description: |- - NamespaceSelectors is the list of namespace selectors to which this ACL applies. - Items in this list are evaluated using a logical OR operation. - items: - description: |- - NamespaceSelector selects the namespaces to which this ACL applies. - An empty map of MatchLabels matches all namespaces in a cluster. - properties: - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - type: array - required: - - namespaceSelectors - type: object - chart: - description: - The name or path the Helm chart is available at in the - SourceRef. - type: string - interval: - description: The interval at which to check the Source for updates. - type: string - reconcileStrategy: - default: ChartVersion - description: |- - Determines what enables the creation of a new artifact. Valid values are - ('ChartVersion', 'Revision'). - See the documentation of the values for an explanation on their behavior. - Defaults to ChartVersion when omitted. - enum: - - ChartVersion - - Revision - type: string - sourceRef: - description: The reference to the Source the chart is available at. - properties: - apiVersion: - description: APIVersion of the referent. - type: string - kind: - description: |- - Kind of the referent, valid values are ('HelmRepository', 'GitRepository', - 'Bucket'). - enum: - - HelmRepository - - GitRepository - - Bucket - type: string - name: - description: Name of the referent. - type: string - required: - - kind - - name - type: object - suspend: - description: - This flag tells the controller to suspend the reconciliation - of this source. - type: boolean - valuesFile: - description: |- - Alternative values file to use as the default chart values, expected to - be a relative path in the SourceRef. Deprecated in favor of ValuesFiles, - for backwards compatibility the file defined here is merged before the - ValuesFiles items. Ignored when omitted. - type: string - valuesFiles: - description: |- - Alternative list of values files to use as the chart values (values.yaml - is not included by default), expected to be a relative path in the SourceRef. - Values files are merged in the order of this list with the last file overriding - the first. Ignored when omitted. - items: - type: string - type: array - version: - default: "*" - description: |- - The chart version semver expression, ignored for charts from GitRepository - and Bucket sources. Defaults to latest when omitted. - type: string - required: - - chart - - interval - - sourceRef - type: object - status: - default: - observedGeneration: -1 - description: HelmChartStatus defines the observed state of the HelmChart. - properties: - artifact: - description: - Artifact represents the output of the last successful - chart sync. - properties: - checksum: - description: Checksum is the SHA256 checksum of the artifact. - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of this - artifact. - format: date-time - type: string - path: - description: Path is the relative file path of this artifact. - type: string - revision: - description: |- - Revision is a human readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm index timestamp, a Helm - chart version, etc. - type: string - url: - description: URL is the HTTP address of this artifact. - type: string - required: - - lastUpdateTime - - path - - url - type: object - conditions: - description: Conditions holds the conditions for the HelmChart. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - url: - description: URL is the download link for the last chart pulled. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .spec.chart - name: Chart - type: string - - jsonPath: .spec.version - name: Version - type: string - - jsonPath: .spec.sourceRef.kind - name: Source Kind - type: string - - jsonPath: .spec.sourceRef.name - name: Source Name - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta2 HelmChart is deprecated, upgrade to v1 - name: v1beta2 - schema: - openAPIV3Schema: - description: HelmChart is the Schema for the helmcharts API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: HelmChartSpec specifies the desired state of a Helm chart. - properties: - accessFrom: - description: |- - AccessFrom specifies an Access Control List for allowing cross-namespace - references to this object. - NOTE: Not implemented, provisional as of https://github.com/fluxcd/flux2/pull/2092 - properties: - namespaceSelectors: - description: |- - NamespaceSelectors is the list of namespace selectors to which this ACL applies. - Items in this list are evaluated using a logical OR operation. - items: - description: |- - NamespaceSelector selects the namespaces to which this ACL applies. - An empty map of MatchLabels matches all namespaces in a cluster. - properties: - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - type: array - required: - - namespaceSelectors - type: object - chart: - description: |- - Chart is the name or path the Helm chart is available at in the - SourceRef. - type: string - ignoreMissingValuesFiles: - description: |- - IgnoreMissingValuesFiles controls whether to silently ignore missing values - files rather than failing. - type: boolean - interval: - description: |- - Interval at which the HelmChart SourceRef is checked for updates. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - reconcileStrategy: - default: ChartVersion - description: |- - ReconcileStrategy determines what enables the creation of a new artifact. - Valid values are ('ChartVersion', 'Revision'). - See the documentation of the values for an explanation on their behavior. - Defaults to ChartVersion when omitted. - enum: - - ChartVersion - - Revision - type: string - sourceRef: - description: - SourceRef is the reference to the Source the chart is - available at. - properties: - apiVersion: - description: APIVersion of the referent. - type: string - kind: - description: |- - Kind of the referent, valid values are ('HelmRepository', 'GitRepository', - 'Bucket'). - enum: - - HelmRepository - - GitRepository - - Bucket - type: string - name: - description: Name of the referent. - type: string - required: - - kind - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend the reconciliation of this - source. - type: boolean - valuesFile: - description: |- - ValuesFile is an alternative values file to use as the default chart - values, expected to be a relative path in the SourceRef. Deprecated in - favor of ValuesFiles, for backwards compatibility the file specified here - is merged before the ValuesFiles items. Ignored when omitted. - type: string - valuesFiles: - description: |- - ValuesFiles is an alternative list of values files to use as the chart - values (values.yaml is not included by default), expected to be a - relative path in the SourceRef. - Values files are merged in the order of this list with the last file - overriding the first. Ignored when omitted. - items: - type: string - type: array - verify: - description: |- - Verify contains the secret name containing the trusted public keys - used to verify the signature and specifies which provider to use to check - whether OCI image is authentic. - This field is only supported when using HelmRepository source with spec.type 'oci'. - Chart dependencies, which are not bundled in the umbrella chart artifact, are not verified. - properties: - matchOIDCIdentity: - description: |- - MatchOIDCIdentity specifies the identity matching criteria to use - while verifying an OCI artifact which was signed using Cosign keyless - signing. The artifact's identity is deemed to be verified if any of the - specified matchers match against the identity. - items: - description: |- - OIDCIdentityMatch specifies options for verifying the certificate identity, - i.e. the issuer and the subject of the certificate. - properties: - issuer: - description: |- - Issuer specifies the regex pattern to match against to verify - the OIDC issuer in the Fulcio certificate. The pattern must be a - valid Go regular expression. - type: string - subject: - description: |- - Subject specifies the regex pattern to match against to verify - the identity subject in the Fulcio certificate. The pattern must - be a valid Go regular expression. - type: string - required: - - issuer - - subject - type: object - type: array - provider: - default: cosign - description: - Provider specifies the technology used to sign the - OCI Artifact. - enum: - - cosign - - notation - type: string - secretRef: - description: |- - SecretRef specifies the Kubernetes Secret containing the - trusted public keys. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - provider - type: object - version: - default: "*" - description: |- - Version is the chart version semver expression, ignored for charts from - GitRepository and Bucket sources. Defaults to latest when omitted. - type: string - required: - - chart - - interval - - sourceRef - type: object - status: - default: - observedGeneration: -1 - description: HelmChartStatus records the observed state of the HelmChart. - properties: - artifact: - description: - Artifact represents the output of the last successful - reconciliation. - properties: - digest: - description: Digest is the digest of the file in the form of ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: Metadata holds upstream information such as OCI annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - conditions: - description: Conditions holds the conditions for the HelmChart. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedChartName: - description: |- - ObservedChartName is the last observed chart name as specified by the - resolved chart reference. - type: string - observedGeneration: - description: |- - ObservedGeneration is the last observed generation of the HelmChart - object. - format: int64 - type: integer - observedSourceArtifactRevision: - description: |- - ObservedSourceArtifactRevision is the last observed Artifact.Revision - of the HelmChartSpec.SourceRef. - type: string - observedValuesFiles: - description: |- - ObservedValuesFiles are the observed value files of the last successful - reconciliation. - It matches the chart in the last successfully reconciled artifact. - items: - type: string - type: array - url: - description: |- - URL is the dynamic fetch link for the latest Artifact. - It is provided on a "best effort" basis, and using the precise - BucketStatus.Artifact data is recommended. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: source-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: helmrepositories.source.toolkit.fluxcd.io -spec: - group: source.toolkit.fluxcd.io - names: - kind: HelmRepository - listKind: HelmRepositoryList - plural: helmrepositories - shortNames: - - helmrepo - singular: helmrepository - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.url - name: URL - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - name: v1 - schema: - openAPIV3Schema: - description: HelmRepository is the Schema for the helmrepositories API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: |- - HelmRepositorySpec specifies the required configuration to produce an - Artifact for a Helm repository index YAML. - properties: - accessFrom: - description: |- - AccessFrom specifies an Access Control List for allowing cross-namespace - references to this object. - NOTE: Not implemented, provisional as of https://github.com/fluxcd/flux2/pull/2092 - properties: - namespaceSelectors: - description: |- - NamespaceSelectors is the list of namespace selectors to which this ACL applies. - Items in this list are evaluated using a logical OR operation. - items: - description: |- - NamespaceSelector selects the namespaces to which this ACL applies. - An empty map of MatchLabels matches all namespaces in a cluster. - properties: - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - type: array - required: - - namespaceSelectors - type: object - certSecretRef: - description: |- - CertSecretRef can be given the name of a Secret containing - either or both of - - - a PEM-encoded client certificate (`tls.crt`) and private - key (`tls.key`); - - a PEM-encoded CA certificate (`ca.crt`) - - and whichever are supplied, will be used for connecting to the - registry. The client cert and key are useful if you are - authenticating with a certificate; the CA cert is useful if - you are using a self-signed server certificate. The Secret must - be of type `Opaque` or `kubernetes.io/tls`. - - It takes precedence over the values specified in the Secret referred - to by `.spec.secretRef`. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - insecure: - description: |- - Insecure allows connecting to a non-TLS HTTP container registry. - This field is only taken into account if the .spec.type field is set to 'oci'. - type: boolean - interval: - description: |- - Interval at which the HelmRepository URL is checked for updates. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - passCredentials: - description: |- - PassCredentials allows the credentials from the SecretRef to be passed - on to a host that does not match the host as defined in URL. - This may be required if the host of the advertised chart URLs in the - index differ from the defined URL. - Enabling this should be done with caution, as it can potentially result - in credentials getting stolen in a MITM-attack. - type: boolean - provider: - default: generic - description: |- - Provider used for authentication, can be 'aws', 'azure', 'gcp' or 'generic'. - This field is optional, and only taken into account if the .spec.type field is set to 'oci'. - When not specified, defaults to 'generic'. - enum: - - generic - - aws - - azure - - gcp - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing authentication credentials - for the HelmRepository. - For HTTP/S basic auth the secret must contain 'username' and 'password' - fields. - Support for TLS auth using the 'certFile' and 'keyFile', and/or 'caFile' - keys is deprecated. Please use `.spec.certSecretRef` instead. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend the reconciliation of this - HelmRepository. - type: boolean - timeout: - description: |- - Timeout is used for the index fetch operation for an HTTPS helm repository, - and for remote OCI Repository operations like pulling for an OCI helm - chart by the associated HelmChart. - Its default value is 60s. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - type: - description: |- - Type of the HelmRepository. - When this field is set to "oci", the URL field value must be prefixed with "oci://". - enum: - - default - - oci - type: string - url: - description: |- - URL of the Helm repository, a valid URL contains at least a protocol and - host. - pattern: ^(http|https|oci)://.*$ - type: string - required: - - url - type: object - status: - default: - observedGeneration: -1 - description: HelmRepositoryStatus records the observed state of the HelmRepository. - properties: - artifact: - description: - Artifact represents the last successful HelmRepository - reconciliation. - properties: - digest: - description: Digest is the digest of the file in the form of ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: Metadata holds upstream information such as OCI annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - conditions: - description: Conditions holds the conditions for the HelmRepository. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: |- - ObservedGeneration is the last observed generation of the HelmRepository - object. - format: int64 - type: integer - url: - description: |- - URL is the dynamic fetch link for the latest Artifact. - It is provided on a "best effort" basis, and using the precise - HelmRepositoryStatus.Artifact data is recommended. - type: string - type: object - type: object - served: true - storage: true - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .spec.url - name: URL - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - deprecated: true - deprecationWarning: v1beta1 HelmRepository is deprecated, upgrade to v1 - name: v1beta1 - schema: - openAPIV3Schema: - description: HelmRepository is the Schema for the helmrepositories API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: HelmRepositorySpec defines the reference to a Helm repository. - properties: - accessFrom: - description: - AccessFrom defines an Access Control List for allowing - cross-namespace references to this object. - properties: - namespaceSelectors: - description: |- - NamespaceSelectors is the list of namespace selectors to which this ACL applies. - Items in this list are evaluated using a logical OR operation. - items: - description: |- - NamespaceSelector selects the namespaces to which this ACL applies. - An empty map of MatchLabels matches all namespaces in a cluster. - properties: - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - type: array - required: - - namespaceSelectors - type: object - interval: - description: The interval at which to check the upstream for updates. - type: string - passCredentials: - description: |- - PassCredentials allows the credentials from the SecretRef to be passed on to - a host that does not match the host as defined in URL. - This may be required if the host of the advertised chart URLs in the index - differ from the defined URL. - Enabling this should be done with caution, as it can potentially result in - credentials getting stolen in a MITM-attack. - type: boolean - secretRef: - description: |- - The name of the secret containing authentication credentials for the Helm - repository. - For HTTP/S basic auth the secret must contain username and - password fields. - For TLS the secret must contain a certFile and keyFile, and/or - caFile fields. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: - This flag tells the controller to suspend the reconciliation - of this source. - type: boolean - timeout: - default: 60s - description: The timeout of index downloading, defaults to 60s. - type: string - url: - description: - The Helm repository URL, a valid URL contains at least - a protocol and host. - type: string - required: - - interval - - url - type: object - status: - default: - observedGeneration: -1 - description: HelmRepositoryStatus defines the observed state of the HelmRepository. - properties: - artifact: - description: - Artifact represents the output of the last successful - repository sync. - properties: - checksum: - description: Checksum is the SHA256 checksum of the artifact. - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of this - artifact. - format: date-time - type: string - path: - description: Path is the relative file path of this artifact. - type: string - revision: - description: |- - Revision is a human readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm index timestamp, a Helm - chart version, etc. - type: string - url: - description: URL is the HTTP address of this artifact. - type: string - required: - - lastUpdateTime - - path - - url - type: object - conditions: - description: Conditions holds the conditions for the HelmRepository. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - url: - description: URL is the download link for the last index fetched. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .spec.url - name: URL - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta2 HelmRepository is deprecated, upgrade to v1 - name: v1beta2 - schema: - openAPIV3Schema: - description: HelmRepository is the Schema for the helmrepositories API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: |- - HelmRepositorySpec specifies the required configuration to produce an - Artifact for a Helm repository index YAML. - properties: - accessFrom: - description: |- - AccessFrom specifies an Access Control List for allowing cross-namespace - references to this object. - NOTE: Not implemented, provisional as of https://github.com/fluxcd/flux2/pull/2092 - properties: - namespaceSelectors: - description: |- - NamespaceSelectors is the list of namespace selectors to which this ACL applies. - Items in this list are evaluated using a logical OR operation. - items: - description: |- - NamespaceSelector selects the namespaces to which this ACL applies. - An empty map of MatchLabels matches all namespaces in a cluster. - properties: - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - type: object - type: array - required: - - namespaceSelectors - type: object - certSecretRef: - description: |- - CertSecretRef can be given the name of a Secret containing - either or both of - - - a PEM-encoded client certificate (`tls.crt`) and private - key (`tls.key`); - - a PEM-encoded CA certificate (`ca.crt`) - - and whichever are supplied, will be used for connecting to the - registry. The client cert and key are useful if you are - authenticating with a certificate; the CA cert is useful if - you are using a self-signed server certificate. The Secret must - be of type `Opaque` or `kubernetes.io/tls`. - - It takes precedence over the values specified in the Secret referred - to by `.spec.secretRef`. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - insecure: - description: |- - Insecure allows connecting to a non-TLS HTTP container registry. - This field is only taken into account if the .spec.type field is set to 'oci'. - type: boolean - interval: - description: |- - Interval at which the HelmRepository URL is checked for updates. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - passCredentials: - description: |- - PassCredentials allows the credentials from the SecretRef to be passed - on to a host that does not match the host as defined in URL. - This may be required if the host of the advertised chart URLs in the - index differ from the defined URL. - Enabling this should be done with caution, as it can potentially result - in credentials getting stolen in a MITM-attack. - type: boolean - provider: - default: generic - description: |- - Provider used for authentication, can be 'aws', 'azure', 'gcp' or 'generic'. - This field is optional, and only taken into account if the .spec.type field is set to 'oci'. - When not specified, defaults to 'generic'. - enum: - - generic - - aws - - azure - - gcp - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing authentication credentials - for the HelmRepository. - For HTTP/S basic auth the secret must contain 'username' and 'password' - fields. - Support for TLS auth using the 'certFile' and 'keyFile', and/or 'caFile' - keys is deprecated. Please use `.spec.certSecretRef` instead. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend the reconciliation of this - HelmRepository. - type: boolean - timeout: - description: |- - Timeout is used for the index fetch operation for an HTTPS helm repository, - and for remote OCI Repository operations like pulling for an OCI helm - chart by the associated HelmChart. - Its default value is 60s. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - type: - description: |- - Type of the HelmRepository. - When this field is set to "oci", the URL field value must be prefixed with "oci://". - enum: - - default - - oci - type: string - url: - description: |- - URL of the Helm repository, a valid URL contains at least a protocol and - host. - pattern: ^(http|https|oci)://.*$ - type: string - required: - - url - type: object - status: - default: - observedGeneration: -1 - description: HelmRepositoryStatus records the observed state of the HelmRepository. - properties: - artifact: - description: - Artifact represents the last successful HelmRepository - reconciliation. - properties: - digest: - description: Digest is the digest of the file in the form of ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: Metadata holds upstream information such as OCI annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - conditions: - description: Conditions holds the conditions for the HelmRepository. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: |- - ObservedGeneration is the last observed generation of the HelmRepository - object. - format: int64 - type: integer - url: - description: |- - URL is the dynamic fetch link for the latest Artifact. - It is provided on a "best effort" basis, and using the precise - HelmRepositoryStatus.Artifact data is recommended. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: source-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: ocirepositories.source.toolkit.fluxcd.io -spec: - group: source.toolkit.fluxcd.io - names: - kind: OCIRepository - listKind: OCIRepositoryList - plural: ocirepositories - shortNames: - - ocirepo - singular: ocirepository - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .spec.url - name: URL - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - name: v1beta2 - schema: - openAPIV3Schema: - description: OCIRepository is the Schema for the ocirepositories API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: OCIRepositorySpec defines the desired state of OCIRepository - properties: - certSecretRef: - description: |- - CertSecretRef can be given the name of a Secret containing - either or both of - - - a PEM-encoded client certificate (`tls.crt`) and private - key (`tls.key`); - - a PEM-encoded CA certificate (`ca.crt`) - - and whichever are supplied, will be used for connecting to the - registry. The client cert and key are useful if you are - authenticating with a certificate; the CA cert is useful if - you are using a self-signed server certificate. The Secret must - be of type `Opaque` or `kubernetes.io/tls`. - - Note: Support for the `caFile`, `certFile` and `keyFile` keys have - been deprecated. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - ignore: - description: |- - Ignore overrides the set of excluded patterns in the .sourceignore format - (which is the same as .gitignore). If not provided, a default will be used, - consult the documentation for your version to find out what those are. - type: string - insecure: - description: - Insecure allows connecting to a non-TLS HTTP container - registry. - type: boolean - interval: - description: |- - Interval at which the OCIRepository URL is checked for updates. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - layerSelector: - description: |- - LayerSelector specifies which layer should be extracted from the OCI artifact. - When not specified, the first layer found in the artifact is selected. - properties: - mediaType: - description: |- - MediaType specifies the OCI media type of the layer - which should be extracted from the OCI Artifact. The - first layer matching this type is selected. - type: string - operation: - description: |- - Operation specifies how the selected layer should be processed. - By default, the layer compressed content is extracted to storage. - When the operation is set to 'copy', the layer compressed content - is persisted to storage as it is. - enum: - - extract - - copy - type: string - type: object - provider: - default: generic - description: |- - The provider used for authentication, can be 'aws', 'azure', 'gcp' or 'generic'. - When not specified, defaults to 'generic'. - enum: - - generic - - aws - - azure - - gcp - type: string - proxySecretRef: - description: |- - ProxySecretRef specifies the Secret containing the proxy configuration - to use while communicating with the container registry. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - ref: - description: |- - The OCI reference to pull and monitor for changes, - defaults to the latest tag. - properties: - digest: - description: |- - Digest is the image digest to pull, takes precedence over SemVer. - The value should be in the format 'sha256:'. - type: string - semver: - description: |- - SemVer is the range of tags to pull selecting the latest within - the range, takes precedence over Tag. - type: string - semverFilter: - description: - SemverFilter is a regex pattern to filter the tags - within the SemVer range. - type: string - tag: - description: Tag is the image tag to pull, defaults to latest. - type: string - type: object - secretRef: - description: |- - SecretRef contains the secret name containing the registry login - credentials to resolve image metadata. - The secret must be of type kubernetes.io/dockerconfigjson. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - serviceAccountName: - description: |- - ServiceAccountName is the name of the Kubernetes ServiceAccount used to authenticate - the image pull if the service account has attached pull secrets. For more information: - https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/#add-imagepullsecrets-to-a-service-account - type: string - suspend: - description: - This flag tells the controller to suspend the reconciliation - of this source. - type: boolean - timeout: - default: 60s - description: - The timeout for remote OCI Repository operations like - pulling, defaults to 60s. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - url: - description: |- - URL is a reference to an OCI artifact repository hosted - on a remote container registry. - pattern: ^oci://.*$ - type: string - verify: - description: |- - Verify contains the secret name containing the trusted public keys - used to verify the signature and specifies which provider to use to check - whether OCI image is authentic. - properties: - matchOIDCIdentity: - description: |- - MatchOIDCIdentity specifies the identity matching criteria to use - while verifying an OCI artifact which was signed using Cosign keyless - signing. The artifact's identity is deemed to be verified if any of the - specified matchers match against the identity. - items: - description: |- - OIDCIdentityMatch specifies options for verifying the certificate identity, - i.e. the issuer and the subject of the certificate. - properties: - issuer: - description: |- - Issuer specifies the regex pattern to match against to verify - the OIDC issuer in the Fulcio certificate. The pattern must be a - valid Go regular expression. - type: string - subject: - description: |- - Subject specifies the regex pattern to match against to verify - the identity subject in the Fulcio certificate. The pattern must - be a valid Go regular expression. - type: string - required: - - issuer - - subject - type: object - type: array - provider: - default: cosign - description: - Provider specifies the technology used to sign the - OCI Artifact. - enum: - - cosign - - notation - type: string - secretRef: - description: |- - SecretRef specifies the Kubernetes Secret containing the - trusted public keys. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - provider - type: object - required: - - interval - - url - type: object - status: - default: - observedGeneration: -1 - description: OCIRepositoryStatus defines the observed state of OCIRepository - properties: - artifact: - description: - Artifact represents the output of the last successful - OCI Repository sync. - properties: - digest: - description: Digest is the digest of the file in the form of ':'. - pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$ - type: string - lastUpdateTime: - description: |- - LastUpdateTime is the timestamp corresponding to the last update of the - Artifact. - format: date-time - type: string - metadata: - additionalProperties: - type: string - description: Metadata holds upstream information such as OCI annotations. - type: object - path: - description: |- - Path is the relative file path of the Artifact. It can be used to locate - the file in the root of the Artifact storage on the local file system of - the controller managing the Source. - type: string - revision: - description: |- - Revision is a human-readable identifier traceable in the origin source - system. It can be a Git commit SHA, Git tag, a Helm chart version, etc. - type: string - size: - description: Size is the number of bytes in the file. - format: int64 - type: integer - url: - description: |- - URL is the HTTP address of the Artifact as exposed by the controller - managing the Source. It can be used to retrieve the Artifact for - consumption, e.g. by another controller applying the Artifact contents. - type: string - required: - - lastUpdateTime - - path - - revision - - url - type: object - conditions: - description: Conditions holds the conditions for the OCIRepository. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - contentConfigChecksum: - description: |- - ContentConfigChecksum is a checksum of all the configurations related to - the content of the source artifact: - - .spec.ignore - - .spec.layerSelector - observed in .status.observedGeneration version of the object. This can - be used to determine if the content configuration has changed and the - artifact needs to be rebuilt. - It has the format of `:`, for example: `sha256:`. - - Deprecated: Replaced with explicit fields for observed artifact content - config in the status. - type: string - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - observedIgnore: - description: |- - ObservedIgnore is the observed exclusion patterns used for constructing - the source artifact. - type: string - observedLayerSelector: - description: |- - ObservedLayerSelector is the observed layer selector used for constructing - the source artifact. - properties: - mediaType: - description: |- - MediaType specifies the OCI media type of the layer - which should be extracted from the OCI Artifact. The - first layer matching this type is selected. - type: string - operation: - description: |- - Operation specifies how the selected layer should be processed. - By default, the layer compressed content is extracted to storage. - When the operation is set to 'copy', the layer compressed content - is persisted to storage as it is. - enum: - - extract - - copy - type: string - type: object - url: - description: - URL is the download link for the artifact output of the - last OCI Repository sync. - type: string - type: object - type: object - served: true - storage: true - subresources: - status: {} ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - labels: - app.kubernetes.io/component: source-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: source-controller - namespace: flux-system ---- -apiVersion: v1 -kind: Service -metadata: - labels: - app.kubernetes.io/component: source-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - control-plane: controller - name: source-controller - namespace: flux-system -spec: - ports: - - name: http - port: 80 - protocol: TCP - targetPort: http - selector: - app: source-controller - type: ClusterIP ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - labels: - app.kubernetes.io/component: source-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - control-plane: controller - name: source-controller - namespace: flux-system -spec: - replicas: 1 - selector: - matchLabels: - app: source-controller - strategy: - type: Recreate - template: - metadata: - annotations: - prometheus.io/port: "8080" - prometheus.io/scrape: "true" - labels: - app: source-controller - spec: - containers: - - args: - - --events-addr=http://notification-controller.flux-system.svc.cluster.local./ - - --watch-all-namespaces=true - - --log-level=info - - --log-encoding=json - - --enable-leader-election - - --storage-path=/data - - --storage-adv-addr=source-controller.$(RUNTIME_NAMESPACE).svc.cluster.local. - env: - - name: RUNTIME_NAMESPACE - valueFrom: - fieldRef: - fieldPath: metadata.namespace - - name: TUF_ROOT - value: /tmp/.sigstore - - name: GOMAXPROCS - valueFrom: - resourceFieldRef: - containerName: manager - resource: limits.cpu - - name: GOMEMLIMIT - valueFrom: - resourceFieldRef: - containerName: manager - resource: limits.memory - image: ghcr.io/fluxcd/source-controller:v1.5.0 - imagePullPolicy: IfNotPresent - livenessProbe: - httpGet: - path: /healthz - port: healthz - name: manager - ports: - - containerPort: 9090 - name: http - protocol: TCP - - containerPort: 8080 - name: http-prom - protocol: TCP - - containerPort: 9440 - name: healthz - protocol: TCP - readinessProbe: - httpGet: - path: / - port: http - resources: - limits: - cpu: 1000m - memory: 1Gi - requests: - cpu: 50m - memory: 64Mi - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - readOnlyRootFilesystem: true - runAsNonRoot: true - seccompProfile: - type: RuntimeDefault - volumeMounts: - - mountPath: /data - name: data - - mountPath: /tmp - name: tmp - nodeSelector: - kubernetes.io/os: linux - priorityClassName: system-cluster-critical - securityContext: - fsGroup: 1337 - serviceAccountName: source-controller - terminationGracePeriodSeconds: 10 - volumes: - - emptyDir: {} - name: data - - emptyDir: {} - name: tmp ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: kustomize-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: kustomizations.kustomize.toolkit.fluxcd.io -spec: - group: kustomize.toolkit.fluxcd.io - names: - kind: Kustomization - listKind: KustomizationList - plural: kustomizations - shortNames: - - ks - singular: kustomization - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - name: v1 - schema: - openAPIV3Schema: - description: Kustomization is the Schema for the kustomizations API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: |- - KustomizationSpec defines the configuration to calculate the desired state - from a Source using Kustomize. - properties: - commonMetadata: - description: |- - CommonMetadata specifies the common labels and annotations that are - applied to all resources. Any existing label or annotation will be - overridden if its key matches a common one. - properties: - annotations: - additionalProperties: - type: string - description: Annotations to be added to the object's metadata. - type: object - labels: - additionalProperties: - type: string - description: Labels to be added to the object's metadata. - type: object - type: object - components: - description: - Components specifies relative paths to specifications - of other Components. - items: - type: string - type: array - decryption: - description: - Decrypt Kubernetes secrets before applying them on the - cluster. - properties: - provider: - description: Provider is the name of the decryption engine. - enum: - - sops - type: string - secretRef: - description: - The secret name containing the private OpenPGP keys - used for decryption. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - provider - type: object - deletionPolicy: - description: |- - DeletionPolicy can be used to control garbage collection when this - Kustomization is deleted. Valid values are ('MirrorPrune', 'Delete', - 'Orphan'). 'MirrorPrune' mirrors the Prune field (orphan if false, - delete if true). Defaults to 'MirrorPrune'. - enum: - - MirrorPrune - - Delete - - Orphan - type: string - dependsOn: - description: |- - DependsOn may contain a meta.NamespacedObjectReference slice - with references to Kustomization resources that must be ready before this - Kustomization can be reconciled. - items: - description: |- - NamespacedObjectReference contains enough information to locate the referenced Kubernetes resource object in any - namespace. - properties: - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, when not specified it - acts as LocalObjectReference. - type: string - required: - - name - type: object - type: array - force: - default: false - description: |- - Force instructs the controller to recreate resources - when patching fails due to an immutable field change. - type: boolean - healthCheckExprs: - description: |- - HealthCheckExprs is a list of healthcheck expressions for evaluating the - health of custom resources using Common Expression Language (CEL). - The expressions are evaluated only when Wait or HealthChecks are specified. - items: - description: - CustomHealthCheck defines the health check for custom - resources. - properties: - apiVersion: - description: APIVersion of the custom resource under evaluation. - type: string - current: - description: |- - Current is the CEL expression that determines if the status - of the custom resource has reached the desired state. - type: string - failed: - description: |- - Failed is the CEL expression that determines if the status - of the custom resource has failed to reach the desired state. - type: string - inProgress: - description: |- - InProgress is the CEL expression that determines if the status - of the custom resource has not yet reached the desired state. - type: string - kind: - description: Kind of the custom resource under evaluation. - type: string - required: - - apiVersion - - current - - kind - type: object - type: array - healthChecks: - description: A list of resources to be included in the health assessment. - items: - description: |- - NamespacedObjectKindReference contains enough information to locate the typed referenced Kubernetes resource object - in any namespace. - properties: - apiVersion: - description: - API version of the referent, if not specified the - Kubernetes preferred version will be used. - type: string - kind: - description: Kind of the referent. - type: string - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, when not specified it - acts as LocalObjectReference. - type: string - required: - - kind - - name - type: object - type: array - images: - description: |- - Images is a list of (image name, new name, new tag or digest) - for changing image names, tags or digests. This can also be achieved with a - patch, but this operator is simpler to specify. - items: - description: - Image contains an image name, a new name, a new tag - or digest, which will replace the original name and tag. - properties: - digest: - description: |- - Digest is the value used to replace the original image tag. - If digest is present NewTag value is ignored. - type: string - name: - description: Name is a tag-less image name. - type: string - newName: - description: - NewName is the value used to replace the original - name. - type: string - newTag: - description: - NewTag is the value used to replace the original - tag. - type: string - required: - - name - type: object - type: array - interval: - description: |- - The interval at which to reconcile the Kustomization. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - kubeConfig: - description: |- - The KubeConfig for reconciling the Kustomization on a remote cluster. - When used in combination with KustomizationSpec.ServiceAccountName, - forces the controller to act on behalf of that Service Account at the - target cluster. - If the --default-service-account flag is set, its value will be used as - a controller level fallback for when KustomizationSpec.ServiceAccountName - is empty. - properties: - secretRef: - description: |- - SecretRef holds the name of a secret that contains a key with - the kubeconfig file as the value. If no key is set, the key will default - to 'value'. - It is recommended that the kubeconfig is self-contained, and the secret - is regularly updated if credentials such as a cloud-access-token expire. - Cloud specific `cmd-path` auth helpers will not function without adding - binaries and credentials to the Pod that is responsible for reconciling - Kubernetes resources. - properties: - key: - description: - Key in the Secret, when not specified an implementation-specific - default key is used. - type: string - name: - description: Name of the Secret. - type: string - required: - - name - type: object - required: - - secretRef - type: object - namePrefix: - description: NamePrefix will prefix the names of all managed resources. - maxLength: 200 - minLength: 1 - type: string - nameSuffix: - description: NameSuffix will suffix the names of all managed resources. - maxLength: 200 - minLength: 1 - type: string - patches: - description: |- - Strategic merge and JSON patches, defined as inline YAML objects, - capable of targeting objects based on kind, label and annotation selectors. - items: - description: |- - Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should - be applied to. - properties: - patch: - description: |- - Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with - an array of operation objects. - type: string - target: - description: - Target points to the resources that the patch document - should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - type: object - type: array - path: - description: |- - Path to the directory containing the kustomization.yaml file, or the - set of plain YAMLs a kustomization.yaml should be generated for. - Defaults to 'None', which translates to the root path of the SourceRef. - type: string - postBuild: - description: |- - PostBuild describes which actions to perform on the YAML manifest - generated by building the kustomize overlay. - properties: - substitute: - additionalProperties: - type: string - description: |- - Substitute holds a map of key/value pairs. - The variables defined in your YAML manifests that match any of the keys - defined in the map will be substituted with the set value. - Includes support for bash string replacement functions - e.g. ${var:=default}, ${var:position} and ${var/substring/replacement}. - type: object - substituteFrom: - description: |- - SubstituteFrom holds references to ConfigMaps and Secrets containing - the variables and their values to be substituted in the YAML manifests. - The ConfigMap and the Secret data keys represent the var names, and they - must match the vars declared in the manifests for the substitution to - happen. - items: - description: |- - SubstituteReference contains a reference to a resource containing - the variables name and value. - properties: - kind: - description: - Kind of the values referent, valid values are - ('Secret', 'ConfigMap'). - enum: - - Secret - - ConfigMap - type: string - name: - description: |- - Name of the values referent. Should reside in the same namespace as the - referring resource. - maxLength: 253 - minLength: 1 - type: string - optional: - default: false - description: |- - Optional indicates whether the referenced resource must exist, or whether to - tolerate its absence. If true and the referenced resource is absent, proceed - as if the resource was present but empty, without any variables defined. - type: boolean - required: - - kind - - name - type: object - type: array - type: object - prune: - description: Prune enables garbage collection. - type: boolean - retryInterval: - description: |- - The interval at which to retry a previously failed reconciliation. - When not specified, the controller uses the KustomizationSpec.Interval - value to retry failures. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - serviceAccountName: - description: |- - The name of the Kubernetes service account to impersonate - when reconciling this Kustomization. - type: string - sourceRef: - description: - Reference of the source where the kustomization file - is. - properties: - apiVersion: - description: API version of the referent. - type: string - kind: - description: Kind of the referent. - enum: - - OCIRepository - - GitRepository - - Bucket - type: string - name: - description: Name of the referent. - type: string - namespace: - description: |- - Namespace of the referent, defaults to the namespace of the Kubernetes - resource object that contains the reference. - type: string - required: - - kind - - name - type: object - suspend: - description: |- - This flag tells the controller to suspend subsequent kustomize executions, - it does not apply to already started executions. Defaults to false. - type: boolean - targetNamespace: - description: |- - TargetNamespace sets or overrides the namespace in the - kustomization.yaml file. - maxLength: 63 - minLength: 1 - type: string - timeout: - description: |- - Timeout for validation, apply and health checking operations. - Defaults to 'Interval' duration. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - wait: - description: |- - Wait instructs the controller to check the health of all the reconciled - resources. When enabled, the HealthChecks are ignored. Defaults to false. - type: boolean - required: - - interval - - prune - - sourceRef - type: object - status: - default: - observedGeneration: -1 - description: KustomizationStatus defines the observed state of a kustomization. - properties: - conditions: - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - inventory: - description: |- - Inventory contains the list of Kubernetes resource object references that - have been successfully applied. - properties: - entries: - description: Entries of Kubernetes resource object references. - items: - description: - ResourceRef contains the information necessary - to locate a resource within a cluster. - properties: - id: - description: |- - ID is the string representation of the Kubernetes resource object's metadata, - in the format '___'. - type: string - v: - description: - Version is the API version of the Kubernetes - resource object's kind. - type: string - required: - - id - - v - type: object - type: array - required: - - entries - type: object - lastAppliedOriginRevision: - description: |- - The last successfully applied origin revision. - Equals the origin revision of the applied Artifact from the referenced Source. - Usually present on the Metadata of the applied Artifact and depends on the - Source type, e.g. for OCI it's the value associated with the key - "org.opencontainers.image.revision". - type: string - lastAppliedRevision: - description: |- - The last successfully applied revision. - Equals the Revision of the applied Artifact from the referenced Source. - type: string - lastAttemptedRevision: - description: - LastAttemptedRevision is the revision of the last reconciliation - attempt. - type: string - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last reconciled generation. - format: int64 - type: integer - type: object - type: object - served: true - storage: true - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - deprecated: true - deprecationWarning: v1beta1 Kustomization is deprecated, upgrade to v1 - name: v1beta1 - schema: - openAPIV3Schema: - description: Kustomization is the Schema for the kustomizations API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: KustomizationSpec defines the desired state of a kustomization. - properties: - decryption: - description: - Decrypt Kubernetes secrets before applying them on the - cluster. - properties: - provider: - description: Provider is the name of the decryption engine. - enum: - - sops - type: string - secretRef: - description: - The secret name containing the private OpenPGP keys - used for decryption. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - provider - type: object - dependsOn: - description: |- - DependsOn may contain a meta.NamespacedObjectReference slice - with references to Kustomization resources that must be ready before this - Kustomization can be reconciled. - items: - description: |- - NamespacedObjectReference contains enough information to locate the referenced Kubernetes resource object in any - namespace. - properties: - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, when not specified it - acts as LocalObjectReference. - type: string - required: - - name - type: object - type: array - force: - default: false - description: |- - Force instructs the controller to recreate resources - when patching fails due to an immutable field change. - type: boolean - healthChecks: - description: A list of resources to be included in the health assessment. - items: - description: |- - NamespacedObjectKindReference contains enough information to locate the typed referenced Kubernetes resource object - in any namespace. - properties: - apiVersion: - description: - API version of the referent, if not specified the - Kubernetes preferred version will be used. - type: string - kind: - description: Kind of the referent. - type: string - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, when not specified it - acts as LocalObjectReference. - type: string - required: - - kind - - name - type: object - type: array - images: - description: |- - Images is a list of (image name, new name, new tag or digest) - for changing image names, tags or digests. This can also be achieved with a - patch, but this operator is simpler to specify. - items: - description: - Image contains an image name, a new name, a new tag - or digest, which will replace the original name and tag. - properties: - digest: - description: |- - Digest is the value used to replace the original image tag. - If digest is present NewTag value is ignored. - type: string - name: - description: Name is a tag-less image name. - type: string - newName: - description: - NewName is the value used to replace the original - name. - type: string - newTag: - description: - NewTag is the value used to replace the original - tag. - type: string - required: - - name - type: object - type: array - interval: - description: The interval at which to reconcile the Kustomization. - type: string - kubeConfig: - description: |- - The KubeConfig for reconciling the Kustomization on a remote cluster. - When specified, KubeConfig takes precedence over ServiceAccountName. - properties: - secretRef: - description: |- - SecretRef holds the name to a secret that contains a 'value' key with - the kubeconfig file as the value. It must be in the same namespace as - the Kustomization. - It is recommended that the kubeconfig is self-contained, and the secret - is regularly updated if credentials such as a cloud-access-token expire. - Cloud specific `cmd-path` auth helpers will not function without adding - binaries and credentials to the Pod that is responsible for reconciling - the Kustomization. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - secretRef - type: object - patches: - description: |- - Strategic merge and JSON patches, defined as inline YAML objects, - capable of targeting objects based on kind, label and annotation selectors. - items: - description: |- - Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should - be applied to. - properties: - patch: - description: |- - Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with - an array of operation objects. - type: string - target: - description: - Target points to the resources that the patch document - should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - type: object - type: array - patchesJson6902: - description: JSON 6902 patches, defined as inline YAML objects. - items: - description: - JSON6902Patch contains a JSON6902 patch and the target - the patch should be applied to. - properties: - patch: - description: - Patch contains the JSON6902 patch document with - an array of operation objects. - items: - description: |- - JSON6902 is a JSON6902 operation object. - https://datatracker.ietf.org/doc/html/rfc6902#section-4 - properties: - from: - description: |- - From contains a JSON-pointer value that references a location within the target document where the operation is - performed. The meaning of the value depends on the value of Op, and is NOT taken into account by all operations. - type: string - op: - description: |- - Op indicates the operation to perform. Its value MUST be one of "add", "remove", "replace", "move", "copy", or - "test". - https://datatracker.ietf.org/doc/html/rfc6902#section-4 - enum: - - test - - remove - - add - - replace - - move - - copy - type: string - path: - description: |- - Path contains the JSON-pointer value that references a location within the target document where the operation - is performed. The meaning of the value depends on the value of Op. - type: string - value: - description: |- - Value contains a valid JSON structure. The meaning of the value depends on the value of Op, and is NOT taken into - account by all operations. - x-kubernetes-preserve-unknown-fields: true - required: - - op - - path - type: object - type: array - target: - description: - Target points to the resources that the patch document - should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - - target - type: object - type: array - patchesStrategicMerge: - description: Strategic merge patches, defined as inline YAML objects. - items: - x-kubernetes-preserve-unknown-fields: true - type: array - path: - description: |- - Path to the directory containing the kustomization.yaml file, or the - set of plain YAMLs a kustomization.yaml should be generated for. - Defaults to 'None', which translates to the root path of the SourceRef. - type: string - postBuild: - description: |- - PostBuild describes which actions to perform on the YAML manifest - generated by building the kustomize overlay. - properties: - substitute: - additionalProperties: - type: string - description: |- - Substitute holds a map of key/value pairs. - The variables defined in your YAML manifests - that match any of the keys defined in the map - will be substituted with the set value. - Includes support for bash string replacement functions - e.g. ${var:=default}, ${var:position} and ${var/substring/replacement}. - type: object - substituteFrom: - description: |- - SubstituteFrom holds references to ConfigMaps and Secrets containing - the variables and their values to be substituted in the YAML manifests. - The ConfigMap and the Secret data keys represent the var names and they - must match the vars declared in the manifests for the substitution to happen. - items: - description: |- - SubstituteReference contains a reference to a resource containing - the variables name and value. - properties: - kind: - description: - Kind of the values referent, valid values are - ('Secret', 'ConfigMap'). - enum: - - Secret - - ConfigMap - type: string - name: - description: |- - Name of the values referent. Should reside in the same namespace as the - referring resource. - maxLength: 253 - minLength: 1 - type: string - required: - - kind - - name - type: object - type: array - type: object - prune: - description: Prune enables garbage collection. - type: boolean - retryInterval: - description: |- - The interval at which to retry a previously failed reconciliation. - When not specified, the controller uses the KustomizationSpec.Interval - value to retry failures. - type: string - serviceAccountName: - description: |- - The name of the Kubernetes service account to impersonate - when reconciling this Kustomization. - type: string - sourceRef: - description: - Reference of the source where the kustomization file - is. - properties: - apiVersion: - description: API version of the referent - type: string - kind: - description: Kind of the referent - enum: - - GitRepository - - Bucket - type: string - name: - description: Name of the referent - type: string - namespace: - description: - Namespace of the referent, defaults to the Kustomization - namespace - type: string - required: - - kind - - name - type: object - suspend: - description: |- - This flag tells the controller to suspend subsequent kustomize executions, - it does not apply to already started executions. Defaults to false. - type: boolean - targetNamespace: - description: |- - TargetNamespace sets or overrides the namespace in the - kustomization.yaml file. - maxLength: 63 - minLength: 1 - type: string - timeout: - description: |- - Timeout for validation, apply and health checking operations. - Defaults to 'Interval' duration. - type: string - validation: - description: |- - Validate the Kubernetes objects before applying them on the cluster. - The validation strategy can be 'client' (local dry-run), 'server' - (APIServer dry-run) or 'none'. - When 'Force' is 'true', validation will fallback to 'client' if set to - 'server' because server-side validation is not supported in this scenario. - enum: - - none - - client - - server - type: string - required: - - interval - - prune - - sourceRef - type: object - status: - default: - observedGeneration: -1 - description: KustomizationStatus defines the observed state of a kustomization. - properties: - conditions: - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastAppliedRevision: - description: |- - The last successfully applied revision. - The revision format for Git sources is /. - type: string - lastAttemptedRevision: - description: - LastAttemptedRevision is the revision of the last reconciliation - attempt. - type: string - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last reconciled generation. - format: int64 - type: integer - snapshot: - description: The last successfully applied revision metadata. - properties: - checksum: - description: The manifests sha1 checksum. - type: string - entries: - description: A list of Kubernetes kinds grouped by namespace. - items: - description: |- - Snapshot holds the metadata of namespaced - Kubernetes objects - properties: - kinds: - additionalProperties: - type: string - description: The list of Kubernetes kinds. - type: object - namespace: - description: The namespace of this entry. - type: string - required: - - kinds - type: object - type: array - required: - - checksum - - entries - type: object - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta2 Kustomization is deprecated, upgrade to v1 - name: v1beta2 - schema: - openAPIV3Schema: - description: Kustomization is the Schema for the kustomizations API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: - KustomizationSpec defines the configuration to calculate - the desired state from a Source using Kustomize. - properties: - commonMetadata: - description: |- - CommonMetadata specifies the common labels and annotations that are applied to all resources. - Any existing label or annotation will be overridden if its key matches a common one. - properties: - annotations: - additionalProperties: - type: string - description: Annotations to be added to the object's metadata. - type: object - labels: - additionalProperties: - type: string - description: Labels to be added to the object's metadata. - type: object - type: object - components: - description: - Components specifies relative paths to specifications - of other Components. - items: - type: string - type: array - decryption: - description: - Decrypt Kubernetes secrets before applying them on the - cluster. - properties: - provider: - description: Provider is the name of the decryption engine. - enum: - - sops - type: string - secretRef: - description: - The secret name containing the private OpenPGP keys - used for decryption. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - provider - type: object - dependsOn: - description: |- - DependsOn may contain a meta.NamespacedObjectReference slice - with references to Kustomization resources that must be ready before this - Kustomization can be reconciled. - items: - description: |- - NamespacedObjectReference contains enough information to locate the referenced Kubernetes resource object in any - namespace. - properties: - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, when not specified it - acts as LocalObjectReference. - type: string - required: - - name - type: object - type: array - force: - default: false - description: |- - Force instructs the controller to recreate resources - when patching fails due to an immutable field change. - type: boolean - healthChecks: - description: A list of resources to be included in the health assessment. - items: - description: |- - NamespacedObjectKindReference contains enough information to locate the typed referenced Kubernetes resource object - in any namespace. - properties: - apiVersion: - description: - API version of the referent, if not specified the - Kubernetes preferred version will be used. - type: string - kind: - description: Kind of the referent. - type: string - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, when not specified it - acts as LocalObjectReference. - type: string - required: - - kind - - name - type: object - type: array - images: - description: |- - Images is a list of (image name, new name, new tag or digest) - for changing image names, tags or digests. This can also be achieved with a - patch, but this operator is simpler to specify. - items: - description: - Image contains an image name, a new name, a new tag - or digest, which will replace the original name and tag. - properties: - digest: - description: |- - Digest is the value used to replace the original image tag. - If digest is present NewTag value is ignored. - type: string - name: - description: Name is a tag-less image name. - type: string - newName: - description: - NewName is the value used to replace the original - name. - type: string - newTag: - description: - NewTag is the value used to replace the original - tag. - type: string - required: - - name - type: object - type: array - interval: - description: The interval at which to reconcile the Kustomization. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - kubeConfig: - description: |- - The KubeConfig for reconciling the Kustomization on a remote cluster. - When used in combination with KustomizationSpec.ServiceAccountName, - forces the controller to act on behalf of that Service Account at the - target cluster. - If the --default-service-account flag is set, its value will be used as - a controller level fallback for when KustomizationSpec.ServiceAccountName - is empty. - properties: - secretRef: - description: |- - SecretRef holds the name of a secret that contains a key with - the kubeconfig file as the value. If no key is set, the key will default - to 'value'. - It is recommended that the kubeconfig is self-contained, and the secret - is regularly updated if credentials such as a cloud-access-token expire. - Cloud specific `cmd-path` auth helpers will not function without adding - binaries and credentials to the Pod that is responsible for reconciling - Kubernetes resources. - properties: - key: - description: - Key in the Secret, when not specified an implementation-specific - default key is used. - type: string - name: - description: Name of the Secret. - type: string - required: - - name - type: object - required: - - secretRef - type: object - patches: - description: |- - Strategic merge and JSON patches, defined as inline YAML objects, - capable of targeting objects based on kind, label and annotation selectors. - items: - description: |- - Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should - be applied to. - properties: - patch: - description: |- - Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with - an array of operation objects. - type: string - target: - description: - Target points to the resources that the patch document - should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - type: object - type: array - patchesJson6902: - description: |- - JSON 6902 patches, defined as inline YAML objects. - Deprecated: Use Patches instead. - items: - description: - JSON6902Patch contains a JSON6902 patch and the target - the patch should be applied to. - properties: - patch: - description: - Patch contains the JSON6902 patch document with - an array of operation objects. - items: - description: |- - JSON6902 is a JSON6902 operation object. - https://datatracker.ietf.org/doc/html/rfc6902#section-4 - properties: - from: - description: |- - From contains a JSON-pointer value that references a location within the target document where the operation is - performed. The meaning of the value depends on the value of Op, and is NOT taken into account by all operations. - type: string - op: - description: |- - Op indicates the operation to perform. Its value MUST be one of "add", "remove", "replace", "move", "copy", or - "test". - https://datatracker.ietf.org/doc/html/rfc6902#section-4 - enum: - - test - - remove - - add - - replace - - move - - copy - type: string - path: - description: |- - Path contains the JSON-pointer value that references a location within the target document where the operation - is performed. The meaning of the value depends on the value of Op. - type: string - value: - description: |- - Value contains a valid JSON structure. The meaning of the value depends on the value of Op, and is NOT taken into - account by all operations. - x-kubernetes-preserve-unknown-fields: true - required: - - op - - path - type: object - type: array - target: - description: - Target points to the resources that the patch document - should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - - target - type: object - type: array - patchesStrategicMerge: - description: |- - Strategic merge patches, defined as inline YAML objects. - Deprecated: Use Patches instead. - items: - x-kubernetes-preserve-unknown-fields: true - type: array - path: - description: |- - Path to the directory containing the kustomization.yaml file, or the - set of plain YAMLs a kustomization.yaml should be generated for. - Defaults to 'None', which translates to the root path of the SourceRef. - type: string - postBuild: - description: |- - PostBuild describes which actions to perform on the YAML manifest - generated by building the kustomize overlay. - properties: - substitute: - additionalProperties: - type: string - description: |- - Substitute holds a map of key/value pairs. - The variables defined in your YAML manifests - that match any of the keys defined in the map - will be substituted with the set value. - Includes support for bash string replacement functions - e.g. ${var:=default}, ${var:position} and ${var/substring/replacement}. - type: object - substituteFrom: - description: |- - SubstituteFrom holds references to ConfigMaps and Secrets containing - the variables and their values to be substituted in the YAML manifests. - The ConfigMap and the Secret data keys represent the var names and they - must match the vars declared in the manifests for the substitution to happen. - items: - description: |- - SubstituteReference contains a reference to a resource containing - the variables name and value. - properties: - kind: - description: - Kind of the values referent, valid values are - ('Secret', 'ConfigMap'). - enum: - - Secret - - ConfigMap - type: string - name: - description: |- - Name of the values referent. Should reside in the same namespace as the - referring resource. - maxLength: 253 - minLength: 1 - type: string - optional: - default: false - description: |- - Optional indicates whether the referenced resource must exist, or whether to - tolerate its absence. If true and the referenced resource is absent, proceed - as if the resource was present but empty, without any variables defined. - type: boolean - required: - - kind - - name - type: object - type: array - type: object - prune: - description: Prune enables garbage collection. - type: boolean - retryInterval: - description: |- - The interval at which to retry a previously failed reconciliation. - When not specified, the controller uses the KustomizationSpec.Interval - value to retry failures. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - serviceAccountName: - description: |- - The name of the Kubernetes service account to impersonate - when reconciling this Kustomization. - type: string - sourceRef: - description: - Reference of the source where the kustomization file - is. - properties: - apiVersion: - description: API version of the referent. - type: string - kind: - description: Kind of the referent. - enum: - - OCIRepository - - GitRepository - - Bucket - type: string - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, defaults to the namespace - of the Kubernetes resource object that contains the reference. - type: string - required: - - kind - - name - type: object - suspend: - description: |- - This flag tells the controller to suspend subsequent kustomize executions, - it does not apply to already started executions. Defaults to false. - type: boolean - targetNamespace: - description: |- - TargetNamespace sets or overrides the namespace in the - kustomization.yaml file. - maxLength: 63 - minLength: 1 - type: string - timeout: - description: |- - Timeout for validation, apply and health checking operations. - Defaults to 'Interval' duration. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - validation: - description: "Deprecated: Not used in v1beta2." - enum: - - none - - client - - server - type: string - wait: - description: |- - Wait instructs the controller to check the health of all the reconciled resources. - When enabled, the HealthChecks are ignored. Defaults to false. - type: boolean - required: - - interval - - prune - - sourceRef - type: object - status: - default: - observedGeneration: -1 - description: KustomizationStatus defines the observed state of a kustomization. - properties: - conditions: - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - inventory: - description: - Inventory contains the list of Kubernetes resource object - references that have been successfully applied. - properties: - entries: - description: Entries of Kubernetes resource object references. - items: - description: - ResourceRef contains the information necessary - to locate a resource within a cluster. - properties: - id: - description: |- - ID is the string representation of the Kubernetes resource object's metadata, - in the format '___'. - type: string - v: - description: - Version is the API version of the Kubernetes - resource object's kind. - type: string - required: - - id - - v - type: object - type: array - required: - - entries - type: object - lastAppliedRevision: - description: |- - The last successfully applied revision. - Equals the Revision of the applied Artifact from the referenced Source. - type: string - lastAttemptedRevision: - description: - LastAttemptedRevision is the revision of the last reconciliation - attempt. - type: string - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last reconciled generation. - format: int64 - type: integer - type: object - type: object - served: true - storage: false - subresources: - status: {} ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - labels: - app.kubernetes.io/component: kustomize-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: kustomize-controller - namespace: flux-system ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - labels: - app.kubernetes.io/component: kustomize-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - control-plane: controller - name: kustomize-controller - namespace: flux-system -spec: - replicas: 1 - selector: - matchLabels: - app: kustomize-controller - template: - metadata: - annotations: - prometheus.io/port: "8080" - prometheus.io/scrape: "true" - labels: - app: kustomize-controller - spec: - containers: - - args: - - --events-addr=http://notification-controller.flux-system.svc.cluster.local./ - - --watch-all-namespaces=true - - --log-level=info - - --log-encoding=json - - --enable-leader-election - env: - - name: RUNTIME_NAMESPACE - valueFrom: - fieldRef: - fieldPath: metadata.namespace - - name: GOMAXPROCS - valueFrom: - resourceFieldRef: - containerName: manager - resource: limits.cpu - - name: GOMEMLIMIT - valueFrom: - resourceFieldRef: - containerName: manager - resource: limits.memory - image: ghcr.io/fluxcd/kustomize-controller:v1.5.1 - imagePullPolicy: IfNotPresent - livenessProbe: - httpGet: - path: /healthz - port: healthz - name: manager - ports: - - containerPort: 8080 - name: http-prom - protocol: TCP - - containerPort: 9440 - name: healthz - protocol: TCP - readinessProbe: - httpGet: - path: /readyz - port: healthz - resources: - limits: - cpu: 1000m - memory: 1Gi - requests: - cpu: 100m - memory: 64Mi - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - readOnlyRootFilesystem: true - runAsNonRoot: true - seccompProfile: - type: RuntimeDefault - volumeMounts: - - mountPath: /tmp - name: temp - nodeSelector: - kubernetes.io/os: linux - priorityClassName: system-cluster-critical - securityContext: - fsGroup: 1337 - serviceAccountName: kustomize-controller - terminationGracePeriodSeconds: 60 - volumes: - - emptyDir: {} - name: temp ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: helm-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: helmreleases.helm.toolkit.fluxcd.io -spec: - group: helm.toolkit.fluxcd.io - names: - kind: HelmRelease - listKind: HelmReleaseList - plural: helmreleases - shortNames: - - hr - singular: helmrelease - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - name: v2 - schema: - openAPIV3Schema: - description: HelmRelease is the Schema for the helmreleases API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: HelmReleaseSpec defines the desired state of a Helm release. - properties: - chart: - description: |- - Chart defines the template of the v1.HelmChart that should be created - for this HelmRelease. - properties: - metadata: - description: - ObjectMeta holds the template for metadata like labels - and annotations. - properties: - annotations: - additionalProperties: - type: string - description: |- - Annotations is an unstructured key value map stored with a resource that may be - set by external tools to store and retrieve arbitrary metadata. They are not - queryable and should be preserved when modifying objects. - More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ - type: object - labels: - additionalProperties: - type: string - description: |- - Map of string keys and values that can be used to organize and categorize - (scope and select) objects. - More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ - type: object - type: object - spec: - description: - Spec holds the template for the v1.HelmChartSpec - for this HelmRelease. - properties: - chart: - description: - The name or path the Helm chart is available - at in the SourceRef. - maxLength: 2048 - minLength: 1 - type: string - ignoreMissingValuesFiles: - description: - IgnoreMissingValuesFiles controls whether to - silently ignore missing values files rather than failing. - type: boolean - interval: - description: |- - Interval at which to check the v1.Source for updates. Defaults to - 'HelmReleaseSpec.Interval'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - reconcileStrategy: - default: ChartVersion - description: |- - Determines what enables the creation of a new artifact. Valid values are - ('ChartVersion', 'Revision'). - See the documentation of the values for an explanation on their behavior. - Defaults to ChartVersion when omitted. - enum: - - ChartVersion - - Revision - type: string - sourceRef: - description: - The name and namespace of the v1.Source the chart - is available at. - properties: - apiVersion: - description: APIVersion of the referent. - type: string - kind: - description: Kind of the referent. - enum: - - HelmRepository - - GitRepository - - Bucket - type: string - name: - description: Name of the referent. - maxLength: 253 - minLength: 1 - type: string - namespace: - description: Namespace of the referent. - maxLength: 63 - minLength: 1 - type: string - required: - - kind - - name - type: object - valuesFiles: - description: |- - Alternative list of values files to use as the chart values (values.yaml - is not included by default), expected to be a relative path in the SourceRef. - Values files are merged in the order of this list with the last file overriding - the first. Ignored when omitted. - items: - type: string - type: array - verify: - description: |- - Verify contains the secret name containing the trusted public keys - used to verify the signature and specifies which provider to use to check - whether OCI image is authentic. - This field is only supported for OCI sources. - Chart dependencies, which are not bundled in the umbrella chart artifact, - are not verified. - properties: - provider: - default: cosign - description: - Provider specifies the technology used to - sign the OCI Helm chart. - enum: - - cosign - - notation - type: string - secretRef: - description: |- - SecretRef specifies the Kubernetes Secret containing the - trusted public keys. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - provider - type: object - version: - default: "*" - description: |- - Version semver expression, ignored for charts from v1.GitRepository and - v1beta2.Bucket sources. Defaults to latest when omitted. - type: string - required: - - chart - - sourceRef - type: object - required: - - spec - type: object - chartRef: - description: |- - ChartRef holds a reference to a source controller resource containing the - Helm chart artifact. - properties: - apiVersion: - description: APIVersion of the referent. - type: string - kind: - description: Kind of the referent. - enum: - - OCIRepository - - HelmChart - type: string - name: - description: Name of the referent. - maxLength: 253 - minLength: 1 - type: string - namespace: - description: |- - Namespace of the referent, defaults to the namespace of the Kubernetes - resource object that contains the reference. - maxLength: 63 - minLength: 1 - type: string - required: - - kind - - name - type: object - dependsOn: - description: |- - DependsOn may contain a meta.NamespacedObjectReference slice with - references to HelmRelease resources that must be ready before this HelmRelease - can be reconciled. - items: - description: |- - NamespacedObjectReference contains enough information to locate the referenced Kubernetes resource object in any - namespace. - properties: - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, when not specified it - acts as LocalObjectReference. - type: string - required: - - name - type: object - type: array - driftDetection: - description: |- - DriftDetection holds the configuration for detecting and handling - differences between the manifest in the Helm storage and the resources - currently existing in the cluster. - properties: - ignore: - description: |- - Ignore contains a list of rules for specifying which changes to ignore - during diffing. - items: - description: |- - IgnoreRule defines a rule to selectively disregard specific changes during - the drift detection process. - properties: - paths: - description: |- - Paths is a list of JSON Pointer (RFC 6901) paths to be excluded from - consideration in a Kubernetes object. - items: - type: string - type: array - target: - description: |- - Target is a selector for specifying Kubernetes objects to which this - rule applies. - If Target is not set, the Paths will be ignored for all Kubernetes - objects within the manifest of the Helm release. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - paths - type: object - type: array - mode: - description: |- - Mode defines how differences should be handled between the Helm manifest - and the manifest currently applied to the cluster. - If not explicitly set, it defaults to DiffModeDisabled. - enum: - - enabled - - warn - - disabled - type: string - type: object - install: - description: - Install holds the configuration for Helm install actions - for this HelmRelease. - properties: - crds: - description: |- - CRDs upgrade CRDs from the Helm Chart's crds directory according - to the CRD upgrade policy provided here. Valid values are `Skip`, - `Create` or `CreateReplace`. Default is `Create` and if omitted - CRDs are installed but not updated. - - Skip: do neither install nor replace (update) any CRDs. - - Create: new CRDs are created, existing CRDs are neither updated nor deleted. - - CreateReplace: new CRDs are created, existing CRDs are updated (replaced) - but not deleted. - - By default, CRDs are applied (installed) during Helm install action. - With this option users can opt in to CRD replace existing CRDs on Helm - install actions, which is not (yet) natively supported by Helm. - https://helm.sh/docs/chart_best_practices/custom_resource_definitions. - enum: - - Skip - - Create - - CreateReplace - type: string - createNamespace: - description: |- - CreateNamespace tells the Helm install action to create the - HelmReleaseSpec.TargetNamespace if it does not exist yet. - On uninstall, the namespace will not be garbage collected. - type: boolean - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm install action. - type: boolean - disableOpenAPIValidation: - description: |- - DisableOpenAPIValidation prevents the Helm install action from validating - rendered templates against the Kubernetes OpenAPI Schema. - type: boolean - disableSchemaValidation: - description: |- - DisableSchemaValidation prevents the Helm install action from validating - the values against the JSON Schema. - type: boolean - disableTakeOwnership: - description: |- - DisableTakeOwnership disables taking ownership of existing resources - during the Helm install action. Defaults to false. - type: boolean - disableWait: - description: |- - DisableWait disables the waiting for resources to be ready after a Helm - install has been performed. - type: boolean - disableWaitForJobs: - description: |- - DisableWaitForJobs disables waiting for jobs to complete after a Helm - install has been performed. - type: boolean - remediation: - description: |- - Remediation holds the remediation configuration for when the Helm install - action for the HelmRelease fails. The default is to not perform any action. - properties: - ignoreTestFailures: - description: |- - IgnoreTestFailures tells the controller to skip remediation when the Helm - tests are run after an install action but fail. Defaults to - 'Test.IgnoreFailures'. - type: boolean - remediateLastFailure: - description: |- - RemediateLastFailure tells the controller to remediate the last failure, when - no retries remain. Defaults to 'false'. - type: boolean - retries: - description: |- - Retries is the number of retries that should be attempted on failures before - bailing. Remediation, using an uninstall, is performed between each attempt. - Defaults to '0', a negative integer equals to unlimited retries. - type: integer - type: object - replace: - description: |- - Replace tells the Helm install action to re-use the 'ReleaseName', but only - if that name is a deleted release which remains in the history. - type: boolean - skipCRDs: - description: |- - SkipCRDs tells the Helm install action to not install any CRDs. By default, - CRDs are installed if not already present. - - Deprecated use CRD policy (`crds`) attribute with value `Skip` instead. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm install action. Defaults to - 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - interval: - description: Interval at which to reconcile the Helm release. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - kubeConfig: - description: |- - KubeConfig for reconciling the HelmRelease on a remote cluster. - When used in combination with HelmReleaseSpec.ServiceAccountName, - forces the controller to act on behalf of that Service Account at the - target cluster. - If the --default-service-account flag is set, its value will be used as - a controller level fallback for when HelmReleaseSpec.ServiceAccountName - is empty. - properties: - secretRef: - description: |- - SecretRef holds the name of a secret that contains a key with - the kubeconfig file as the value. If no key is set, the key will default - to 'value'. - It is recommended that the kubeconfig is self-contained, and the secret - is regularly updated if credentials such as a cloud-access-token expire. - Cloud specific `cmd-path` auth helpers will not function without adding - binaries and credentials to the Pod that is responsible for reconciling - Kubernetes resources. - properties: - key: - description: - Key in the Secret, when not specified an implementation-specific - default key is used. - type: string - name: - description: Name of the Secret. - type: string - required: - - name - type: object - required: - - secretRef - type: object - maxHistory: - description: |- - MaxHistory is the number of revisions saved by Helm for this HelmRelease. - Use '0' for an unlimited number of revisions; defaults to '5'. - type: integer - persistentClient: - description: |- - PersistentClient tells the controller to use a persistent Kubernetes - client for this release. When enabled, the client will be reused for the - duration of the reconciliation, instead of being created and destroyed - for each (step of a) Helm action. - - This can improve performance, but may cause issues with some Helm charts - that for example do create Custom Resource Definitions during installation - outside Helm's CRD lifecycle hooks, which are then not observed to be - available by e.g. post-install hooks. - - If not set, it defaults to true. - type: boolean - postRenderers: - description: |- - PostRenderers holds an array of Helm PostRenderers, which will be applied in order - of their definition. - items: - description: PostRenderer contains a Helm PostRenderer specification. - properties: - kustomize: - description: Kustomization to apply as PostRenderer. - properties: - images: - description: |- - Images is a list of (image name, new name, new tag or digest) - for changing image names, tags or digests. This can also be achieved with a - patch, but this operator is simpler to specify. - items: - description: - Image contains an image name, a new name, - a new tag or digest, which will replace the original - name and tag. - properties: - digest: - description: |- - Digest is the value used to replace the original image tag. - If digest is present NewTag value is ignored. - type: string - name: - description: Name is a tag-less image name. - type: string - newName: - description: - NewName is the value used to replace - the original name. - type: string - newTag: - description: - NewTag is the value used to replace the - original tag. - type: string - required: - - name - type: object - type: array - patches: - description: |- - Strategic merge and JSON patches, defined as inline YAML objects, - capable of targeting objects based on kind, label and annotation selectors. - items: - description: |- - Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should - be applied to. - properties: - patch: - description: |- - Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with - an array of operation objects. - type: string - target: - description: - Target points to the resources that the - patch document should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - type: object - type: array - type: object - type: object - type: array - releaseName: - description: |- - ReleaseName used for the Helm release. Defaults to a composition of - '[TargetNamespace-]Name'. - maxLength: 53 - minLength: 1 - type: string - rollback: - description: - Rollback holds the configuration for Helm rollback actions - for this HelmRelease. - properties: - cleanupOnFail: - description: |- - CleanupOnFail allows deletion of new resources created during the Helm - rollback action when it fails. - type: boolean - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm rollback action. - type: boolean - disableWait: - description: |- - DisableWait disables the waiting for resources to be ready after a Helm - rollback has been performed. - type: boolean - disableWaitForJobs: - description: |- - DisableWaitForJobs disables waiting for jobs to complete after a Helm - rollback has been performed. - type: boolean - force: - description: - Force forces resource updates through a replacement - strategy. - type: boolean - recreate: - description: - Recreate performs pod restarts for the resource if - applicable. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm rollback action. Defaults to - 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - serviceAccountName: - description: |- - The name of the Kubernetes service account to impersonate - when reconciling this HelmRelease. - maxLength: 253 - minLength: 1 - type: string - storageNamespace: - description: |- - StorageNamespace used for the Helm storage. - Defaults to the namespace of the HelmRelease. - maxLength: 63 - minLength: 1 - type: string - suspend: - description: |- - Suspend tells the controller to suspend reconciliation for this HelmRelease, - it does not apply to already started reconciliations. Defaults to false. - type: boolean - targetNamespace: - description: |- - TargetNamespace to target when performing operations for the HelmRelease. - Defaults to the namespace of the HelmRelease. - maxLength: 63 - minLength: 1 - type: string - test: - description: - Test holds the configuration for Helm test actions for - this HelmRelease. - properties: - enable: - description: |- - Enable enables Helm test actions for this HelmRelease after an Helm install - or upgrade action has been performed. - type: boolean - filters: - description: - Filters is a list of tests to run or exclude from - running. - items: - description: - Filter holds the configuration for individual Helm - test filters. - properties: - exclude: - description: - Exclude specifies whether the named test should - be excluded. - type: boolean - name: - description: Name is the name of the test. - maxLength: 253 - minLength: 1 - type: string - required: - - name - type: object - type: array - ignoreFailures: - description: |- - IgnoreFailures tells the controller to skip remediation when the Helm tests - are run but fail. Can be overwritten for tests run after install or upgrade - actions in 'Install.IgnoreTestFailures' and 'Upgrade.IgnoreTestFailures'. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation during - the performance of a Helm test action. Defaults to 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like Jobs - for hooks) during the performance of a Helm action. Defaults to '5m0s'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - uninstall: - description: - Uninstall holds the configuration for Helm uninstall - actions for this HelmRelease. - properties: - deletionPropagation: - default: background - description: |- - DeletionPropagation specifies the deletion propagation policy when - a Helm uninstall is performed. - enum: - - background - - foreground - - orphan - type: string - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm rollback action. - type: boolean - disableWait: - description: |- - DisableWait disables waiting for all the resources to be deleted after - a Helm uninstall is performed. - type: boolean - keepHistory: - description: |- - KeepHistory tells Helm to remove all associated resources and mark the - release as deleted, but retain the release history. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm uninstall action. Defaults - to 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - upgrade: - description: - Upgrade holds the configuration for Helm upgrade actions - for this HelmRelease. - properties: - cleanupOnFail: - description: |- - CleanupOnFail allows deletion of new resources created during the Helm - upgrade action when it fails. - type: boolean - crds: - description: |- - CRDs upgrade CRDs from the Helm Chart's crds directory according - to the CRD upgrade policy provided here. Valid values are `Skip`, - `Create` or `CreateReplace`. Default is `Skip` and if omitted - CRDs are neither installed nor upgraded. - - Skip: do neither install nor replace (update) any CRDs. - - Create: new CRDs are created, existing CRDs are neither updated nor deleted. - - CreateReplace: new CRDs are created, existing CRDs are updated (replaced) - but not deleted. - - By default, CRDs are not applied during Helm upgrade action. With this - option users can opt-in to CRD upgrade, which is not (yet) natively supported by Helm. - https://helm.sh/docs/chart_best_practices/custom_resource_definitions. - enum: - - Skip - - Create - - CreateReplace - type: string - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm upgrade action. - type: boolean - disableOpenAPIValidation: - description: |- - DisableOpenAPIValidation prevents the Helm upgrade action from validating - rendered templates against the Kubernetes OpenAPI Schema. - type: boolean - disableSchemaValidation: - description: |- - DisableSchemaValidation prevents the Helm upgrade action from validating - the values against the JSON Schema. - type: boolean - disableTakeOwnership: - description: |- - DisableTakeOwnership disables taking ownership of existing resources - during the Helm upgrade action. Defaults to false. - type: boolean - disableWait: - description: |- - DisableWait disables the waiting for resources to be ready after a Helm - upgrade has been performed. - type: boolean - disableWaitForJobs: - description: |- - DisableWaitForJobs disables waiting for jobs to complete after a Helm - upgrade has been performed. - type: boolean - force: - description: - Force forces resource updates through a replacement - strategy. - type: boolean - preserveValues: - description: |- - PreserveValues will make Helm reuse the last release's values and merge in - overrides from 'Values'. Setting this flag makes the HelmRelease - non-declarative. - type: boolean - remediation: - description: |- - Remediation holds the remediation configuration for when the Helm upgrade - action for the HelmRelease fails. The default is to not perform any action. - properties: - ignoreTestFailures: - description: |- - IgnoreTestFailures tells the controller to skip remediation when the Helm - tests are run after an upgrade action but fail. - Defaults to 'Test.IgnoreFailures'. - type: boolean - remediateLastFailure: - description: |- - RemediateLastFailure tells the controller to remediate the last failure, when - no retries remain. Defaults to 'false' unless 'Retries' is greater than 0. - type: boolean - retries: - description: |- - Retries is the number of retries that should be attempted on failures before - bailing. Remediation, using 'Strategy', is performed between each attempt. - Defaults to '0', a negative integer equals to unlimited retries. - type: integer - strategy: - description: - Strategy to use for failure remediation. Defaults - to 'rollback'. - enum: - - rollback - - uninstall - type: string - type: object - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm upgrade action. Defaults to - 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - values: - description: Values holds the values for this Helm release. - x-kubernetes-preserve-unknown-fields: true - valuesFrom: - description: |- - ValuesFrom holds references to resources containing Helm values for this HelmRelease, - and information about how they should be merged. - items: - description: |- - ValuesReference contains a reference to a resource containing Helm values, - and optionally the key they can be found at. - properties: - kind: - description: - Kind of the values referent, valid values are ('Secret', - 'ConfigMap'). - enum: - - Secret - - ConfigMap - type: string - name: - description: |- - Name of the values referent. Should reside in the same namespace as the - referring resource. - maxLength: 253 - minLength: 1 - type: string - optional: - description: |- - Optional marks this ValuesReference as optional. When set, a not found error - for the values reference is ignored, but any ValuesKey, TargetPath or - transient error will still result in a reconciliation failure. - type: boolean - targetPath: - description: |- - TargetPath is the YAML dot notation path the value should be merged at. When - set, the ValuesKey is expected to be a single flat value. Defaults to 'None', - which results in the values getting merged at the root. - maxLength: 250 - pattern: ^([a-zA-Z0-9_\-.\\\/]|\[[0-9]{1,5}\])+$ - type: string - valuesKey: - description: |- - ValuesKey is the data key where the values.yaml or a specific value can be - found at. Defaults to 'values.yaml'. - maxLength: 253 - pattern: ^[\-._a-zA-Z0-9]+$ - type: string - required: - - kind - - name - type: object - type: array - required: - - interval - type: object - x-kubernetes-validations: - - message: either chart or chartRef must be set - rule: - (has(self.chart) && !has(self.chartRef)) || (!has(self.chart) - && has(self.chartRef)) - status: - default: - observedGeneration: -1 - description: HelmReleaseStatus defines the observed state of a HelmRelease. - properties: - conditions: - description: Conditions holds the conditions for the HelmRelease. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - failures: - description: |- - Failures is the reconciliation failure count against the latest desired - state. It is reset after a successful reconciliation. - format: int64 - type: integer - helmChart: - description: |- - HelmChart is the namespaced name of the HelmChart resource created by - the controller for the HelmRelease. - type: string - history: - description: |- - History holds the history of Helm releases performed for this HelmRelease - up to the last successfully completed release. - items: - description: |- - Snapshot captures a point-in-time copy of the status information for a Helm release, - as managed by the controller. - properties: - apiVersion: - description: |- - APIVersion is the API version of the Snapshot. - Provisional: when the calculation method of the Digest field is changed, - this field will be used to distinguish between the old and new methods. - type: string - appVersion: - description: - AppVersion is the chart app version of the release - object in storage. - type: string - chartName: - description: - ChartName is the chart name of the release object - in storage. - type: string - chartVersion: - description: |- - ChartVersion is the chart version of the release object in - storage. - type: string - configDigest: - description: |- - ConfigDigest is the checksum of the config (better known as - "values") of the release object in storage. - It has the format of `:`. - type: string - deleted: - description: Deleted is when the release was deleted. - format: date-time - type: string - digest: - description: |- - Digest is the checksum of the release object in storage. - It has the format of `:`. - type: string - firstDeployed: - description: FirstDeployed is when the release was first deployed. - format: date-time - type: string - lastDeployed: - description: LastDeployed is when the release was last deployed. - format: date-time - type: string - name: - description: Name is the name of the release. - type: string - namespace: - description: - Namespace is the namespace the release is deployed - to. - type: string - ociDigest: - description: - OCIDigest is the digest of the OCI artifact associated - with the release. - type: string - status: - description: Status is the current state of the release. - type: string - testHooks: - additionalProperties: - description: |- - TestHookStatus holds the status information for a test hook as observed - to be run by the controller. - properties: - lastCompleted: - description: - LastCompleted is the time the test hook last - completed. - format: date-time - type: string - lastStarted: - description: - LastStarted is the time the test hook was - last started. - format: date-time - type: string - phase: - description: Phase the test hook was observed to be in. - type: string - type: object - description: |- - TestHooks is the list of test hooks for the release as observed to be - run by the controller. - type: object - version: - description: - Version is the version of the release object in - storage. - type: integer - required: - - chartName - - chartVersion - - configDigest - - digest - - firstDeployed - - lastDeployed - - name - - namespace - - status - - version - type: object - type: array - installFailures: - description: |- - InstallFailures is the install failure count against the latest desired - state. It is reset after a successful reconciliation. - format: int64 - type: integer - lastAttemptedConfigDigest: - description: |- - LastAttemptedConfigDigest is the digest for the config (better known as - "values") of the last reconciliation attempt. - type: string - lastAttemptedGeneration: - description: |- - LastAttemptedGeneration is the last generation the controller attempted - to reconcile. - format: int64 - type: integer - lastAttemptedReleaseAction: - description: |- - LastAttemptedReleaseAction is the last release action performed for this - HelmRelease. It is used to determine the active remediation strategy. - enum: - - install - - upgrade - type: string - lastAttemptedRevision: - description: |- - LastAttemptedRevision is the Source revision of the last reconciliation - attempt. For OCIRepository sources, the 12 first characters of the digest are - appended to the chart version e.g. "1.2.3+1234567890ab". - type: string - lastAttemptedRevisionDigest: - description: |- - LastAttemptedRevisionDigest is the digest of the last reconciliation attempt. - This is only set for OCIRepository sources. - type: string - lastAttemptedValuesChecksum: - description: |- - LastAttemptedValuesChecksum is the SHA1 checksum for the values of the last - reconciliation attempt. - Deprecated: Use LastAttemptedConfigDigest instead. - type: string - lastHandledForceAt: - description: |- - LastHandledForceAt holds the value of the most recent force request - value, so a change of the annotation value can be detected. - type: string - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - lastHandledResetAt: - description: |- - LastHandledResetAt holds the value of the most recent reset request - value, so a change of the annotation value can be detected. - type: string - lastReleaseRevision: - description: |- - LastReleaseRevision is the revision of the last successful Helm release. - Deprecated: Use History instead. - type: integer - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - observedPostRenderersDigest: - description: |- - ObservedPostRenderersDigest is the digest for the post-renderers of - the last successful reconciliation attempt. - type: string - storageNamespace: - description: |- - StorageNamespace is the namespace of the Helm release storage for the - current release. - maxLength: 63 - minLength: 1 - type: string - upgradeFailures: - description: |- - UpgradeFailures is the upgrade failure count against the latest desired - state. It is reset after a successful reconciliation. - format: int64 - type: integer - type: object - type: object - served: true - storage: true - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v2beta1 HelmRelease is deprecated, upgrade to v2 - name: v2beta1 - schema: - openAPIV3Schema: - description: HelmRelease is the Schema for the helmreleases API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: HelmReleaseSpec defines the desired state of a Helm release. - properties: - chart: - description: |- - Chart defines the template of the v1beta2.HelmChart that should be created - for this HelmRelease. - properties: - metadata: - description: - ObjectMeta holds the template for metadata like labels - and annotations. - properties: - annotations: - additionalProperties: - type: string - description: |- - Annotations is an unstructured key value map stored with a resource that may be - set by external tools to store and retrieve arbitrary metadata. They are not - queryable and should be preserved when modifying objects. - More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ - type: object - labels: - additionalProperties: - type: string - description: |- - Map of string keys and values that can be used to organize and categorize - (scope and select) objects. - More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ - type: object - type: object - spec: - description: - Spec holds the template for the v1beta2.HelmChartSpec - for this HelmRelease. - properties: - chart: - description: - The name or path the Helm chart is available - at in the SourceRef. - type: string - interval: - description: |- - Interval at which to check the v1beta2.Source for updates. Defaults to - 'HelmReleaseSpec.Interval'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - reconcileStrategy: - default: ChartVersion - description: |- - Determines what enables the creation of a new artifact. Valid values are - ('ChartVersion', 'Revision'). - See the documentation of the values for an explanation on their behavior. - Defaults to ChartVersion when omitted. - enum: - - ChartVersion - - Revision - type: string - sourceRef: - description: - The name and namespace of the v1beta2.Source - the chart is available at. - properties: - apiVersion: - description: APIVersion of the referent. - type: string - kind: - description: Kind of the referent. - enum: - - HelmRepository - - GitRepository - - Bucket - type: string - name: - description: Name of the referent. - maxLength: 253 - minLength: 1 - type: string - namespace: - description: Namespace of the referent. - maxLength: 63 - minLength: 1 - type: string - required: - - kind - - name - type: object - valuesFile: - description: |- - Alternative values file to use as the default chart values, expected to - be a relative path in the SourceRef. Deprecated in favor of ValuesFiles, - for backwards compatibility the file defined here is merged before the - ValuesFiles items. Ignored when omitted. - type: string - valuesFiles: - description: |- - Alternative list of values files to use as the chart values (values.yaml - is not included by default), expected to be a relative path in the SourceRef. - Values files are merged in the order of this list with the last file overriding - the first. Ignored when omitted. - items: - type: string - type: array - verify: - description: |- - Verify contains the secret name containing the trusted public keys - used to verify the signature and specifies which provider to use to check - whether OCI image is authentic. - This field is only supported for OCI sources. - Chart dependencies, which are not bundled in the umbrella chart artifact, are not verified. - properties: - provider: - default: cosign - description: - Provider specifies the technology used to - sign the OCI Helm chart. - enum: - - cosign - type: string - secretRef: - description: |- - SecretRef specifies the Kubernetes Secret containing the - trusted public keys. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - provider - type: object - version: - default: "*" - description: |- - Version semver expression, ignored for charts from v1beta2.GitRepository and - v1beta2.Bucket sources. Defaults to latest when omitted. - type: string - required: - - chart - - sourceRef - type: object - required: - - spec - type: object - chartRef: - description: |- - ChartRef holds a reference to a source controller resource containing the - Helm chart artifact. - - Note: this field is provisional to the v2 API, and not actively used - by v2beta1 HelmReleases. - properties: - apiVersion: - description: APIVersion of the referent. - type: string - kind: - description: Kind of the referent. - enum: - - OCIRepository - - HelmChart - type: string - name: - description: Name of the referent. - maxLength: 253 - minLength: 1 - type: string - namespace: - description: |- - Namespace of the referent, defaults to the namespace of the Kubernetes - resource object that contains the reference. - maxLength: 63 - minLength: 1 - type: string - required: - - kind - - name - type: object - dependsOn: - description: |- - DependsOn may contain a meta.NamespacedObjectReference slice with - references to HelmRelease resources that must be ready before this HelmRelease - can be reconciled. - items: - description: |- - NamespacedObjectReference contains enough information to locate the referenced Kubernetes resource object in any - namespace. - properties: - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, when not specified it - acts as LocalObjectReference. - type: string - required: - - name - type: object - type: array - driftDetection: - description: |- - DriftDetection holds the configuration for detecting and handling - differences between the manifest in the Helm storage and the resources - currently existing in the cluster. - - Note: this field is provisional to the v2beta2 API, and not actively used - by v2beta1 HelmReleases. - properties: - ignore: - description: |- - Ignore contains a list of rules for specifying which changes to ignore - during diffing. - items: - description: |- - IgnoreRule defines a rule to selectively disregard specific changes during - the drift detection process. - properties: - paths: - description: |- - Paths is a list of JSON Pointer (RFC 6901) paths to be excluded from - consideration in a Kubernetes object. - items: - type: string - type: array - target: - description: |- - Target is a selector for specifying Kubernetes objects to which this - rule applies. - If Target is not set, the Paths will be ignored for all Kubernetes - objects within the manifest of the Helm release. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - paths - type: object - type: array - mode: - description: |- - Mode defines how differences should be handled between the Helm manifest - and the manifest currently applied to the cluster. - If not explicitly set, it defaults to DiffModeDisabled. - enum: - - enabled - - warn - - disabled - type: string - type: object - install: - description: - Install holds the configuration for Helm install actions - for this HelmRelease. - properties: - crds: - description: |- - CRDs upgrade CRDs from the Helm Chart's crds directory according - to the CRD upgrade policy provided here. Valid values are `Skip`, - `Create` or `CreateReplace`. Default is `Create` and if omitted - CRDs are installed but not updated. - - Skip: do neither install nor replace (update) any CRDs. - - Create: new CRDs are created, existing CRDs are neither updated nor deleted. - - CreateReplace: new CRDs are created, existing CRDs are updated (replaced) - but not deleted. - - By default, CRDs are applied (installed) during Helm install action. - With this option users can opt-in to CRD replace existing CRDs on Helm - install actions, which is not (yet) natively supported by Helm. - https://helm.sh/docs/chart_best_practices/custom_resource_definitions. - enum: - - Skip - - Create - - CreateReplace - type: string - createNamespace: - description: |- - CreateNamespace tells the Helm install action to create the - HelmReleaseSpec.TargetNamespace if it does not exist yet. - On uninstall, the namespace will not be garbage collected. - type: boolean - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm install action. - type: boolean - disableOpenAPIValidation: - description: |- - DisableOpenAPIValidation prevents the Helm install action from validating - rendered templates against the Kubernetes OpenAPI Schema. - type: boolean - disableWait: - description: |- - DisableWait disables the waiting for resources to be ready after a Helm - install has been performed. - type: boolean - disableWaitForJobs: - description: |- - DisableWaitForJobs disables waiting for jobs to complete after a Helm - install has been performed. - type: boolean - remediation: - description: |- - Remediation holds the remediation configuration for when the Helm install - action for the HelmRelease fails. The default is to not perform any action. - properties: - ignoreTestFailures: - description: |- - IgnoreTestFailures tells the controller to skip remediation when the Helm - tests are run after an install action but fail. Defaults to - 'Test.IgnoreFailures'. - type: boolean - remediateLastFailure: - description: |- - RemediateLastFailure tells the controller to remediate the last failure, when - no retries remain. Defaults to 'false'. - type: boolean - retries: - description: |- - Retries is the number of retries that should be attempted on failures before - bailing. Remediation, using an uninstall, is performed between each attempt. - Defaults to '0', a negative integer equals to unlimited retries. - type: integer - type: object - replace: - description: |- - Replace tells the Helm install action to re-use the 'ReleaseName', but only - if that name is a deleted release which remains in the history. - type: boolean - skipCRDs: - description: |- - SkipCRDs tells the Helm install action to not install any CRDs. By default, - CRDs are installed if not already present. - - Deprecated use CRD policy (`crds`) attribute with value `Skip` instead. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm install action. Defaults to - 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - interval: - description: |- - Interval at which to reconcile the Helm release. - This interval is approximate and may be subject to jitter to ensure - efficient use of resources. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - kubeConfig: - description: |- - KubeConfig for reconciling the HelmRelease on a remote cluster. - When used in combination with HelmReleaseSpec.ServiceAccountName, - forces the controller to act on behalf of that Service Account at the - target cluster. - If the --default-service-account flag is set, its value will be used as - a controller level fallback for when HelmReleaseSpec.ServiceAccountName - is empty. - properties: - secretRef: - description: |- - SecretRef holds the name of a secret that contains a key with - the kubeconfig file as the value. If no key is set, the key will default - to 'value'. - It is recommended that the kubeconfig is self-contained, and the secret - is regularly updated if credentials such as a cloud-access-token expire. - Cloud specific `cmd-path` auth helpers will not function without adding - binaries and credentials to the Pod that is responsible for reconciling - Kubernetes resources. - properties: - key: - description: - Key in the Secret, when not specified an implementation-specific - default key is used. - type: string - name: - description: Name of the Secret. - type: string - required: - - name - type: object - required: - - secretRef - type: object - maxHistory: - description: |- - MaxHistory is the number of revisions saved by Helm for this HelmRelease. - Use '0' for an unlimited number of revisions; defaults to '10'. - type: integer - persistentClient: - description: |- - PersistentClient tells the controller to use a persistent Kubernetes - client for this release. When enabled, the client will be reused for the - duration of the reconciliation, instead of being created and destroyed - for each (step of a) Helm action. - - This can improve performance, but may cause issues with some Helm charts - that for example do create Custom Resource Definitions during installation - outside Helm's CRD lifecycle hooks, which are then not observed to be - available by e.g. post-install hooks. - - If not set, it defaults to true. - type: boolean - postRenderers: - description: |- - PostRenderers holds an array of Helm PostRenderers, which will be applied in order - of their definition. - items: - description: PostRenderer contains a Helm PostRenderer specification. - properties: - kustomize: - description: Kustomization to apply as PostRenderer. - properties: - images: - description: |- - Images is a list of (image name, new name, new tag or digest) - for changing image names, tags or digests. This can also be achieved with a - patch, but this operator is simpler to specify. - items: - description: - Image contains an image name, a new name, - a new tag or digest, which will replace the original - name and tag. - properties: - digest: - description: |- - Digest is the value used to replace the original image tag. - If digest is present NewTag value is ignored. - type: string - name: - description: Name is a tag-less image name. - type: string - newName: - description: - NewName is the value used to replace - the original name. - type: string - newTag: - description: - NewTag is the value used to replace the - original tag. - type: string - required: - - name - type: object - type: array - patches: - description: |- - Strategic merge and JSON patches, defined as inline YAML objects, - capable of targeting objects based on kind, label and annotation selectors. - items: - description: |- - Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should - be applied to. - properties: - patch: - description: |- - Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with - an array of operation objects. - type: string - target: - description: - Target points to the resources that the - patch document should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - type: object - type: array - patchesJson6902: - description: JSON 6902 patches, defined as inline YAML objects. - items: - description: - JSON6902Patch contains a JSON6902 patch and - the target the patch should be applied to. - properties: - patch: - description: - Patch contains the JSON6902 patch document - with an array of operation objects. - items: - description: |- - JSON6902 is a JSON6902 operation object. - https://datatracker.ietf.org/doc/html/rfc6902#section-4 - properties: - from: - description: |- - From contains a JSON-pointer value that references a location within the target document where the operation is - performed. The meaning of the value depends on the value of Op, and is NOT taken into account by all operations. - type: string - op: - description: |- - Op indicates the operation to perform. Its value MUST be one of "add", "remove", "replace", "move", "copy", or - "test". - https://datatracker.ietf.org/doc/html/rfc6902#section-4 - enum: - - test - - remove - - add - - replace - - move - - copy - type: string - path: - description: |- - Path contains the JSON-pointer value that references a location within the target document where the operation - is performed. The meaning of the value depends on the value of Op. - type: string - value: - description: |- - Value contains a valid JSON structure. The meaning of the value depends on the value of Op, and is NOT taken into - account by all operations. - x-kubernetes-preserve-unknown-fields: true - required: - - op - - path - type: object - type: array - target: - description: - Target points to the resources that the - patch document should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - - target - type: object - type: array - patchesStrategicMerge: - description: - Strategic merge patches, defined as inline - YAML objects. - items: - x-kubernetes-preserve-unknown-fields: true - type: array - type: object - type: object - type: array - releaseName: - description: |- - ReleaseName used for the Helm release. Defaults to a composition of - '[TargetNamespace-]Name'. - maxLength: 53 - minLength: 1 - type: string - rollback: - description: - Rollback holds the configuration for Helm rollback actions - for this HelmRelease. - properties: - cleanupOnFail: - description: |- - CleanupOnFail allows deletion of new resources created during the Helm - rollback action when it fails. - type: boolean - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm rollback action. - type: boolean - disableWait: - description: |- - DisableWait disables the waiting for resources to be ready after a Helm - rollback has been performed. - type: boolean - disableWaitForJobs: - description: |- - DisableWaitForJobs disables waiting for jobs to complete after a Helm - rollback has been performed. - type: boolean - force: - description: - Force forces resource updates through a replacement - strategy. - type: boolean - recreate: - description: - Recreate performs pod restarts for the resource if - applicable. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm rollback action. Defaults to - 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - serviceAccountName: - description: |- - The name of the Kubernetes service account to impersonate - when reconciling this HelmRelease. - type: string - storageNamespace: - description: |- - StorageNamespace used for the Helm storage. - Defaults to the namespace of the HelmRelease. - maxLength: 63 - minLength: 1 - type: string - suspend: - description: |- - Suspend tells the controller to suspend reconciliation for this HelmRelease, - it does not apply to already started reconciliations. Defaults to false. - type: boolean - targetNamespace: - description: |- - TargetNamespace to target when performing operations for the HelmRelease. - Defaults to the namespace of the HelmRelease. - maxLength: 63 - minLength: 1 - type: string - test: - description: - Test holds the configuration for Helm test actions for - this HelmRelease. - properties: - enable: - description: |- - Enable enables Helm test actions for this HelmRelease after an Helm install - or upgrade action has been performed. - type: boolean - ignoreFailures: - description: |- - IgnoreFailures tells the controller to skip remediation when the Helm tests - are run but fail. Can be overwritten for tests run after install or upgrade - actions in 'Install.IgnoreTestFailures' and 'Upgrade.IgnoreTestFailures'. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation during - the performance of a Helm test action. Defaults to 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like Jobs - for hooks) during the performance of a Helm action. Defaults to '5m0s'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - uninstall: - description: - Uninstall holds the configuration for Helm uninstall - actions for this HelmRelease. - properties: - deletionPropagation: - default: background - description: |- - DeletionPropagation specifies the deletion propagation policy when - a Helm uninstall is performed. - enum: - - background - - foreground - - orphan - type: string - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm rollback action. - type: boolean - disableWait: - description: |- - DisableWait disables waiting for all the resources to be deleted after - a Helm uninstall is performed. - type: boolean - keepHistory: - description: |- - KeepHistory tells Helm to remove all associated resources and mark the - release as deleted, but retain the release history. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm uninstall action. Defaults - to 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - upgrade: - description: - Upgrade holds the configuration for Helm upgrade actions - for this HelmRelease. - properties: - cleanupOnFail: - description: |- - CleanupOnFail allows deletion of new resources created during the Helm - upgrade action when it fails. - type: boolean - crds: - description: |- - CRDs upgrade CRDs from the Helm Chart's crds directory according - to the CRD upgrade policy provided here. Valid values are `Skip`, - `Create` or `CreateReplace`. Default is `Skip` and if omitted - CRDs are neither installed nor upgraded. - - Skip: do neither install nor replace (update) any CRDs. - - Create: new CRDs are created, existing CRDs are neither updated nor deleted. - - CreateReplace: new CRDs are created, existing CRDs are updated (replaced) - but not deleted. - - By default, CRDs are not applied during Helm upgrade action. With this - option users can opt-in to CRD upgrade, which is not (yet) natively supported by Helm. - https://helm.sh/docs/chart_best_practices/custom_resource_definitions. - enum: - - Skip - - Create - - CreateReplace - type: string - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm upgrade action. - type: boolean - disableOpenAPIValidation: - description: |- - DisableOpenAPIValidation prevents the Helm upgrade action from validating - rendered templates against the Kubernetes OpenAPI Schema. - type: boolean - disableWait: - description: |- - DisableWait disables the waiting for resources to be ready after a Helm - upgrade has been performed. - type: boolean - disableWaitForJobs: - description: |- - DisableWaitForJobs disables waiting for jobs to complete after a Helm - upgrade has been performed. - type: boolean - force: - description: - Force forces resource updates through a replacement - strategy. - type: boolean - preserveValues: - description: |- - PreserveValues will make Helm reuse the last release's values and merge in - overrides from 'Values'. Setting this flag makes the HelmRelease - non-declarative. - type: boolean - remediation: - description: |- - Remediation holds the remediation configuration for when the Helm upgrade - action for the HelmRelease fails. The default is to not perform any action. - properties: - ignoreTestFailures: - description: |- - IgnoreTestFailures tells the controller to skip remediation when the Helm - tests are run after an upgrade action but fail. - Defaults to 'Test.IgnoreFailures'. - type: boolean - remediateLastFailure: - description: |- - RemediateLastFailure tells the controller to remediate the last failure, when - no retries remain. Defaults to 'false' unless 'Retries' is greater than 0. - type: boolean - retries: - description: |- - Retries is the number of retries that should be attempted on failures before - bailing. Remediation, using 'Strategy', is performed between each attempt. - Defaults to '0', a negative integer equals to unlimited retries. - type: integer - strategy: - description: - Strategy to use for failure remediation. Defaults - to 'rollback'. - enum: - - rollback - - uninstall - type: string - type: object - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm upgrade action. Defaults to - 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - values: - description: Values holds the values for this Helm release. - x-kubernetes-preserve-unknown-fields: true - valuesFrom: - description: |- - ValuesFrom holds references to resources containing Helm values for this HelmRelease, - and information about how they should be merged. - items: - description: |- - ValuesReference contains a reference to a resource containing Helm values, - and optionally the key they can be found at. - properties: - kind: - description: - Kind of the values referent, valid values are ('Secret', - 'ConfigMap'). - enum: - - Secret - - ConfigMap - type: string - name: - description: |- - Name of the values referent. Should reside in the same namespace as the - referring resource. - maxLength: 253 - minLength: 1 - type: string - optional: - description: |- - Optional marks this ValuesReference as optional. When set, a not found error - for the values reference is ignored, but any ValuesKey, TargetPath or - transient error will still result in a reconciliation failure. - type: boolean - targetPath: - description: |- - TargetPath is the YAML dot notation path the value should be merged at. When - set, the ValuesKey is expected to be a single flat value. Defaults to 'None', - which results in the values getting merged at the root. - maxLength: 250 - pattern: ^([a-zA-Z0-9_\-.\\\/]|\[[0-9]{1,5}\])+$ - type: string - valuesKey: - description: |- - ValuesKey is the data key where the values.yaml or a specific value can be - found at. Defaults to 'values.yaml'. - When set, must be a valid Data Key, consisting of alphanumeric characters, - '-', '_' or '.'. - maxLength: 253 - pattern: ^[\-._a-zA-Z0-9]+$ - type: string - required: - - kind - - name - type: object - type: array - required: - - chart - - interval - type: object - status: - default: - observedGeneration: -1 - description: HelmReleaseStatus defines the observed state of a HelmRelease. - properties: - conditions: - description: Conditions holds the conditions for the HelmRelease. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - failures: - description: |- - Failures is the reconciliation failure count against the latest desired - state. It is reset after a successful reconciliation. - format: int64 - type: integer - helmChart: - description: |- - HelmChart is the namespaced name of the HelmChart resource created by - the controller for the HelmRelease. - type: string - history: - description: |- - History holds the history of Helm releases performed for this HelmRelease - up to the last successfully completed release. - - Note: this field is provisional to the v2beta2 API, and not actively used - by v2beta1 HelmReleases. - items: - description: |- - Snapshot captures a point-in-time copy of the status information for a Helm release, - as managed by the controller. - properties: - apiVersion: - description: |- - APIVersion is the API version of the Snapshot. - Provisional: when the calculation method of the Digest field is changed, - this field will be used to distinguish between the old and new methods. - type: string - appVersion: - description: - AppVersion is the chart app version of the release - object in storage. - type: string - chartName: - description: - ChartName is the chart name of the release object - in storage. - type: string - chartVersion: - description: |- - ChartVersion is the chart version of the release object in - storage. - type: string - configDigest: - description: |- - ConfigDigest is the checksum of the config (better known as - "values") of the release object in storage. - It has the format of `:`. - type: string - deleted: - description: Deleted is when the release was deleted. - format: date-time - type: string - digest: - description: |- - Digest is the checksum of the release object in storage. - It has the format of `:`. - type: string - firstDeployed: - description: FirstDeployed is when the release was first deployed. - format: date-time - type: string - lastDeployed: - description: LastDeployed is when the release was last deployed. - format: date-time - type: string - name: - description: Name is the name of the release. - type: string - namespace: - description: - Namespace is the namespace the release is deployed - to. - type: string - ociDigest: - description: - OCIDigest is the digest of the OCI artifact associated - with the release. - type: string - status: - description: Status is the current state of the release. - type: string - testHooks: - additionalProperties: - description: |- - TestHookStatus holds the status information for a test hook as observed - to be run by the controller. - properties: - lastCompleted: - description: - LastCompleted is the time the test hook last - completed. - format: date-time - type: string - lastStarted: - description: - LastStarted is the time the test hook was - last started. - format: date-time - type: string - phase: - description: Phase the test hook was observed to be in. - type: string - type: object - description: |- - TestHooks is the list of test hooks for the release as observed to be - run by the controller. - type: object - version: - description: - Version is the version of the release object in - storage. - type: integer - required: - - chartName - - chartVersion - - configDigest - - digest - - firstDeployed - - lastDeployed - - name - - namespace - - status - - version - type: object - type: array - installFailures: - description: |- - InstallFailures is the install failure count against the latest desired - state. It is reset after a successful reconciliation. - format: int64 - type: integer - lastAppliedRevision: - description: - LastAppliedRevision is the revision of the last successfully - applied source. - type: string - lastAttemptedConfigDigest: - description: |- - LastAttemptedConfigDigest is the digest for the config (better known as - "values") of the last reconciliation attempt. - - Note: this field is provisional to the v2beta2 API, and not actively used - by v2beta1 HelmReleases. - type: string - lastAttemptedGeneration: - description: |- - LastAttemptedGeneration is the last generation the controller attempted - to reconcile. - - Note: this field is provisional to the v2beta2 API, and not actively used - by v2beta1 HelmReleases. - format: int64 - type: integer - lastAttemptedReleaseAction: - description: |- - LastAttemptedReleaseAction is the last release action performed for this - HelmRelease. It is used to determine the active remediation strategy. - - Note: this field is provisional to the v2beta2 API, and not actively used - by v2beta1 HelmReleases. - type: string - lastAttemptedRevision: - description: - LastAttemptedRevision is the revision of the last reconciliation - attempt. - type: string - lastAttemptedValuesChecksum: - description: |- - LastAttemptedValuesChecksum is the SHA1 checksum of the values of the last - reconciliation attempt. - type: string - lastHandledForceAt: - description: |- - LastHandledForceAt holds the value of the most recent force request - value, so a change of the annotation value can be detected. - - Note: this field is provisional to the v2beta2 API, and not actively used - by v2beta1 HelmReleases. - type: string - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - lastHandledResetAt: - description: |- - LastHandledResetAt holds the value of the most recent reset request - value, so a change of the annotation value can be detected. - - Note: this field is provisional to the v2beta2 API, and not actively used - by v2beta1 HelmReleases. - type: string - lastReleaseRevision: - description: - LastReleaseRevision is the revision of the last successful - Helm release. - type: integer - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - observedPostRenderersDigest: - description: |- - ObservedPostRenderersDigest is the digest for the post-renderers of - the last successful reconciliation attempt. - type: string - storageNamespace: - description: |- - StorageNamespace is the namespace of the Helm release storage for the - current release. - - Note: this field is provisional to the v2beta2 API, and not actively used - by v2beta1 HelmReleases. - type: string - upgradeFailures: - description: |- - UpgradeFailures is the upgrade failure count against the latest desired - state. It is reset after a successful reconciliation. - format: int64 - type: integer - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v2beta2 HelmRelease is deprecated, upgrade to v2 - name: v2beta2 - schema: - openAPIV3Schema: - description: HelmRelease is the Schema for the helmreleases API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: HelmReleaseSpec defines the desired state of a Helm release. - properties: - chart: - description: |- - Chart defines the template of the v1beta2.HelmChart that should be created - for this HelmRelease. - properties: - metadata: - description: - ObjectMeta holds the template for metadata like labels - and annotations. - properties: - annotations: - additionalProperties: - type: string - description: |- - Annotations is an unstructured key value map stored with a resource that may be - set by external tools to store and retrieve arbitrary metadata. They are not - queryable and should be preserved when modifying objects. - More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ - type: object - labels: - additionalProperties: - type: string - description: |- - Map of string keys and values that can be used to organize and categorize - (scope and select) objects. - More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ - type: object - type: object - spec: - description: - Spec holds the template for the v1beta2.HelmChartSpec - for this HelmRelease. - properties: - chart: - description: - The name or path the Helm chart is available - at in the SourceRef. - maxLength: 2048 - minLength: 1 - type: string - ignoreMissingValuesFiles: - description: - IgnoreMissingValuesFiles controls whether to - silently ignore missing values files rather than failing. - type: boolean - interval: - description: |- - Interval at which to check the v1.Source for updates. Defaults to - 'HelmReleaseSpec.Interval'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - reconcileStrategy: - default: ChartVersion - description: |- - Determines what enables the creation of a new artifact. Valid values are - ('ChartVersion', 'Revision'). - See the documentation of the values for an explanation on their behavior. - Defaults to ChartVersion when omitted. - enum: - - ChartVersion - - Revision - type: string - sourceRef: - description: - The name and namespace of the v1.Source the chart - is available at. - properties: - apiVersion: - description: APIVersion of the referent. - type: string - kind: - description: Kind of the referent. - enum: - - HelmRepository - - GitRepository - - Bucket - type: string - name: - description: Name of the referent. - maxLength: 253 - minLength: 1 - type: string - namespace: - description: Namespace of the referent. - maxLength: 63 - minLength: 1 - type: string - required: - - kind - - name - type: object - valuesFile: - description: |- - Alternative values file to use as the default chart values, expected to - be a relative path in the SourceRef. Deprecated in favor of ValuesFiles, - for backwards compatibility the file defined here is merged before the - ValuesFiles items. Ignored when omitted. - type: string - valuesFiles: - description: |- - Alternative list of values files to use as the chart values (values.yaml - is not included by default), expected to be a relative path in the SourceRef. - Values files are merged in the order of this list with the last file overriding - the first. Ignored when omitted. - items: - type: string - type: array - verify: - description: |- - Verify contains the secret name containing the trusted public keys - used to verify the signature and specifies which provider to use to check - whether OCI image is authentic. - This field is only supported for OCI sources. - Chart dependencies, which are not bundled in the umbrella chart artifact, - are not verified. - properties: - provider: - default: cosign - description: - Provider specifies the technology used to - sign the OCI Helm chart. - enum: - - cosign - - notation - type: string - secretRef: - description: |- - SecretRef specifies the Kubernetes Secret containing the - trusted public keys. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - required: - - provider - type: object - version: - default: "*" - description: |- - Version semver expression, ignored for charts from v1beta2.GitRepository and - v1beta2.Bucket sources. Defaults to latest when omitted. - type: string - required: - - chart - - sourceRef - type: object - required: - - spec - type: object - chartRef: - description: |- - ChartRef holds a reference to a source controller resource containing the - Helm chart artifact. - - Note: this field is provisional to the v2 API, and not actively used - by v2beta2 HelmReleases. - properties: - apiVersion: - description: APIVersion of the referent. - type: string - kind: - description: Kind of the referent. - enum: - - OCIRepository - - HelmChart - type: string - name: - description: Name of the referent. - maxLength: 253 - minLength: 1 - type: string - namespace: - description: |- - Namespace of the referent, defaults to the namespace of the Kubernetes - resource object that contains the reference. - maxLength: 63 - minLength: 1 - type: string - required: - - kind - - name - type: object - dependsOn: - description: |- - DependsOn may contain a meta.NamespacedObjectReference slice with - references to HelmRelease resources that must be ready before this HelmRelease - can be reconciled. - items: - description: |- - NamespacedObjectReference contains enough information to locate the referenced Kubernetes resource object in any - namespace. - properties: - name: - description: Name of the referent. - type: string - namespace: - description: - Namespace of the referent, when not specified it - acts as LocalObjectReference. - type: string - required: - - name - type: object - type: array - driftDetection: - description: |- - DriftDetection holds the configuration for detecting and handling - differences between the manifest in the Helm storage and the resources - currently existing in the cluster. - properties: - ignore: - description: |- - Ignore contains a list of rules for specifying which changes to ignore - during diffing. - items: - description: |- - IgnoreRule defines a rule to selectively disregard specific changes during - the drift detection process. - properties: - paths: - description: |- - Paths is a list of JSON Pointer (RFC 6901) paths to be excluded from - consideration in a Kubernetes object. - items: - type: string - type: array - target: - description: |- - Target is a selector for specifying Kubernetes objects to which this - rule applies. - If Target is not set, the Paths will be ignored for all Kubernetes - objects within the manifest of the Helm release. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - paths - type: object - type: array - mode: - description: |- - Mode defines how differences should be handled between the Helm manifest - and the manifest currently applied to the cluster. - If not explicitly set, it defaults to DiffModeDisabled. - enum: - - enabled - - warn - - disabled - type: string - type: object - install: - description: - Install holds the configuration for Helm install actions - for this HelmRelease. - properties: - crds: - description: |- - CRDs upgrade CRDs from the Helm Chart's crds directory according - to the CRD upgrade policy provided here. Valid values are `Skip`, - `Create` or `CreateReplace`. Default is `Create` and if omitted - CRDs are installed but not updated. - - Skip: do neither install nor replace (update) any CRDs. - - Create: new CRDs are created, existing CRDs are neither updated nor deleted. - - CreateReplace: new CRDs are created, existing CRDs are updated (replaced) - but not deleted. - - By default, CRDs are applied (installed) during Helm install action. - With this option users can opt in to CRD replace existing CRDs on Helm - install actions, which is not (yet) natively supported by Helm. - https://helm.sh/docs/chart_best_practices/custom_resource_definitions. - enum: - - Skip - - Create - - CreateReplace - type: string - createNamespace: - description: |- - CreateNamespace tells the Helm install action to create the - HelmReleaseSpec.TargetNamespace if it does not exist yet. - On uninstall, the namespace will not be garbage collected. - type: boolean - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm install action. - type: boolean - disableOpenAPIValidation: - description: |- - DisableOpenAPIValidation prevents the Helm install action from validating - rendered templates against the Kubernetes OpenAPI Schema. - type: boolean - disableWait: - description: |- - DisableWait disables the waiting for resources to be ready after a Helm - install has been performed. - type: boolean - disableWaitForJobs: - description: |- - DisableWaitForJobs disables waiting for jobs to complete after a Helm - install has been performed. - type: boolean - remediation: - description: |- - Remediation holds the remediation configuration for when the Helm install - action for the HelmRelease fails. The default is to not perform any action. - properties: - ignoreTestFailures: - description: |- - IgnoreTestFailures tells the controller to skip remediation when the Helm - tests are run after an install action but fail. Defaults to - 'Test.IgnoreFailures'. - type: boolean - remediateLastFailure: - description: |- - RemediateLastFailure tells the controller to remediate the last failure, when - no retries remain. Defaults to 'false'. - type: boolean - retries: - description: |- - Retries is the number of retries that should be attempted on failures before - bailing. Remediation, using an uninstall, is performed between each attempt. - Defaults to '0', a negative integer equals to unlimited retries. - type: integer - type: object - replace: - description: |- - Replace tells the Helm install action to re-use the 'ReleaseName', but only - if that name is a deleted release which remains in the history. - type: boolean - skipCRDs: - description: |- - SkipCRDs tells the Helm install action to not install any CRDs. By default, - CRDs are installed if not already present. - - Deprecated use CRD policy (`crds`) attribute with value `Skip` instead. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm install action. Defaults to - 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - interval: - description: Interval at which to reconcile the Helm release. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - kubeConfig: - description: |- - KubeConfig for reconciling the HelmRelease on a remote cluster. - When used in combination with HelmReleaseSpec.ServiceAccountName, - forces the controller to act on behalf of that Service Account at the - target cluster. - If the --default-service-account flag is set, its value will be used as - a controller level fallback for when HelmReleaseSpec.ServiceAccountName - is empty. - properties: - secretRef: - description: |- - SecretRef holds the name of a secret that contains a key with - the kubeconfig file as the value. If no key is set, the key will default - to 'value'. - It is recommended that the kubeconfig is self-contained, and the secret - is regularly updated if credentials such as a cloud-access-token expire. - Cloud specific `cmd-path` auth helpers will not function without adding - binaries and credentials to the Pod that is responsible for reconciling - Kubernetes resources. - properties: - key: - description: - Key in the Secret, when not specified an implementation-specific - default key is used. - type: string - name: - description: Name of the Secret. - type: string - required: - - name - type: object - required: - - secretRef - type: object - maxHistory: - description: |- - MaxHistory is the number of revisions saved by Helm for this HelmRelease. - Use '0' for an unlimited number of revisions; defaults to '5'. - type: integer - persistentClient: - description: |- - PersistentClient tells the controller to use a persistent Kubernetes - client for this release. When enabled, the client will be reused for the - duration of the reconciliation, instead of being created and destroyed - for each (step of a) Helm action. - - This can improve performance, but may cause issues with some Helm charts - that for example do create Custom Resource Definitions during installation - outside Helm's CRD lifecycle hooks, which are then not observed to be - available by e.g. post-install hooks. - - If not set, it defaults to true. - type: boolean - postRenderers: - description: |- - PostRenderers holds an array of Helm PostRenderers, which will be applied in order - of their definition. - items: - description: PostRenderer contains a Helm PostRenderer specification. - properties: - kustomize: - description: Kustomization to apply as PostRenderer. - properties: - images: - description: |- - Images is a list of (image name, new name, new tag or digest) - for changing image names, tags or digests. This can also be achieved with a - patch, but this operator is simpler to specify. - items: - description: - Image contains an image name, a new name, - a new tag or digest, which will replace the original - name and tag. - properties: - digest: - description: |- - Digest is the value used to replace the original image tag. - If digest is present NewTag value is ignored. - type: string - name: - description: Name is a tag-less image name. - type: string - newName: - description: - NewName is the value used to replace - the original name. - type: string - newTag: - description: - NewTag is the value used to replace the - original tag. - type: string - required: - - name - type: object - type: array - patches: - description: |- - Strategic merge and JSON patches, defined as inline YAML objects, - capable of targeting objects based on kind, label and annotation selectors. - items: - description: |- - Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should - be applied to. - properties: - patch: - description: |- - Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with - an array of operation objects. - type: string - target: - description: - Target points to the resources that the - patch document should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - type: object - type: array - patchesJson6902: - description: |- - JSON 6902 patches, defined as inline YAML objects. - Deprecated: use Patches instead. - items: - description: - JSON6902Patch contains a JSON6902 patch and - the target the patch should be applied to. - properties: - patch: - description: - Patch contains the JSON6902 patch document - with an array of operation objects. - items: - description: |- - JSON6902 is a JSON6902 operation object. - https://datatracker.ietf.org/doc/html/rfc6902#section-4 - properties: - from: - description: |- - From contains a JSON-pointer value that references a location within the target document where the operation is - performed. The meaning of the value depends on the value of Op, and is NOT taken into account by all operations. - type: string - op: - description: |- - Op indicates the operation to perform. Its value MUST be one of "add", "remove", "replace", "move", "copy", or - "test". - https://datatracker.ietf.org/doc/html/rfc6902#section-4 - enum: - - test - - remove - - add - - replace - - move - - copy - type: string - path: - description: |- - Path contains the JSON-pointer value that references a location within the target document where the operation - is performed. The meaning of the value depends on the value of Op. - type: string - value: - description: |- - Value contains a valid JSON structure. The meaning of the value depends on the value of Op, and is NOT taken into - account by all operations. - x-kubernetes-preserve-unknown-fields: true - required: - - op - - path - type: object - type: array - target: - description: - Target points to the resources that the - patch document should be applied to. - properties: - annotationSelector: - description: |- - AnnotationSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource annotations. - type: string - group: - description: |- - Group is the API group to select resources from. - Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - kind: - description: |- - Kind of the API Group to select resources from. - Together with Group and Version it is capable of unambiguously - identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - labelSelector: - description: |- - LabelSelector is a string that follows the label selection expression - https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api - It matches with the resource labels. - type: string - name: - description: Name to match resources with. - type: string - namespace: - description: Namespace to select resources from. - type: string - version: - description: |- - Version of the API Group to select resources from. - Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources. - https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md - type: string - type: object - required: - - patch - - target - type: object - type: array - patchesStrategicMerge: - description: |- - Strategic merge patches, defined as inline YAML objects. - Deprecated: use Patches instead. - items: - x-kubernetes-preserve-unknown-fields: true - type: array - type: object - type: object - type: array - releaseName: - description: |- - ReleaseName used for the Helm release. Defaults to a composition of - '[TargetNamespace-]Name'. - maxLength: 53 - minLength: 1 - type: string - rollback: - description: - Rollback holds the configuration for Helm rollback actions - for this HelmRelease. - properties: - cleanupOnFail: - description: |- - CleanupOnFail allows deletion of new resources created during the Helm - rollback action when it fails. - type: boolean - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm rollback action. - type: boolean - disableWait: - description: |- - DisableWait disables the waiting for resources to be ready after a Helm - rollback has been performed. - type: boolean - disableWaitForJobs: - description: |- - DisableWaitForJobs disables waiting for jobs to complete after a Helm - rollback has been performed. - type: boolean - force: - description: - Force forces resource updates through a replacement - strategy. - type: boolean - recreate: - description: - Recreate performs pod restarts for the resource if - applicable. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm rollback action. Defaults to - 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - serviceAccountName: - description: |- - The name of the Kubernetes service account to impersonate - when reconciling this HelmRelease. - maxLength: 253 - minLength: 1 - type: string - storageNamespace: - description: |- - StorageNamespace used for the Helm storage. - Defaults to the namespace of the HelmRelease. - maxLength: 63 - minLength: 1 - type: string - suspend: - description: |- - Suspend tells the controller to suspend reconciliation for this HelmRelease, - it does not apply to already started reconciliations. Defaults to false. - type: boolean - targetNamespace: - description: |- - TargetNamespace to target when performing operations for the HelmRelease. - Defaults to the namespace of the HelmRelease. - maxLength: 63 - minLength: 1 - type: string - test: - description: - Test holds the configuration for Helm test actions for - this HelmRelease. - properties: - enable: - description: |- - Enable enables Helm test actions for this HelmRelease after an Helm install - or upgrade action has been performed. - type: boolean - filters: - description: - Filters is a list of tests to run or exclude from - running. - items: - description: - Filter holds the configuration for individual Helm - test filters. - properties: - exclude: - description: - Exclude specifies whether the named test should - be excluded. - type: boolean - name: - description: Name is the name of the test. - maxLength: 253 - minLength: 1 - type: string - required: - - name - type: object - type: array - ignoreFailures: - description: |- - IgnoreFailures tells the controller to skip remediation when the Helm tests - are run but fail. Can be overwritten for tests run after install or upgrade - actions in 'Install.IgnoreTestFailures' and 'Upgrade.IgnoreTestFailures'. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation during - the performance of a Helm test action. Defaults to 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like Jobs - for hooks) during the performance of a Helm action. Defaults to '5m0s'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - uninstall: - description: - Uninstall holds the configuration for Helm uninstall - actions for this HelmRelease. - properties: - deletionPropagation: - default: background - description: |- - DeletionPropagation specifies the deletion propagation policy when - a Helm uninstall is performed. - enum: - - background - - foreground - - orphan - type: string - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm rollback action. - type: boolean - disableWait: - description: |- - DisableWait disables waiting for all the resources to be deleted after - a Helm uninstall is performed. - type: boolean - keepHistory: - description: |- - KeepHistory tells Helm to remove all associated resources and mark the - release as deleted, but retain the release history. - type: boolean - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm uninstall action. Defaults - to 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - upgrade: - description: - Upgrade holds the configuration for Helm upgrade actions - for this HelmRelease. - properties: - cleanupOnFail: - description: |- - CleanupOnFail allows deletion of new resources created during the Helm - upgrade action when it fails. - type: boolean - crds: - description: |- - CRDs upgrade CRDs from the Helm Chart's crds directory according - to the CRD upgrade policy provided here. Valid values are `Skip`, - `Create` or `CreateReplace`. Default is `Skip` and if omitted - CRDs are neither installed nor upgraded. - - Skip: do neither install nor replace (update) any CRDs. - - Create: new CRDs are created, existing CRDs are neither updated nor deleted. - - CreateReplace: new CRDs are created, existing CRDs are updated (replaced) - but not deleted. - - By default, CRDs are not applied during Helm upgrade action. With this - option users can opt-in to CRD upgrade, which is not (yet) natively supported by Helm. - https://helm.sh/docs/chart_best_practices/custom_resource_definitions. - enum: - - Skip - - Create - - CreateReplace - type: string - disableHooks: - description: - DisableHooks prevents hooks from running during the - Helm upgrade action. - type: boolean - disableOpenAPIValidation: - description: |- - DisableOpenAPIValidation prevents the Helm upgrade action from validating - rendered templates against the Kubernetes OpenAPI Schema. - type: boolean - disableWait: - description: |- - DisableWait disables the waiting for resources to be ready after a Helm - upgrade has been performed. - type: boolean - disableWaitForJobs: - description: |- - DisableWaitForJobs disables waiting for jobs to complete after a Helm - upgrade has been performed. - type: boolean - force: - description: - Force forces resource updates through a replacement - strategy. - type: boolean - preserveValues: - description: |- - PreserveValues will make Helm reuse the last release's values and merge in - overrides from 'Values'. Setting this flag makes the HelmRelease - non-declarative. - type: boolean - remediation: - description: |- - Remediation holds the remediation configuration for when the Helm upgrade - action for the HelmRelease fails. The default is to not perform any action. - properties: - ignoreTestFailures: - description: |- - IgnoreTestFailures tells the controller to skip remediation when the Helm - tests are run after an upgrade action but fail. - Defaults to 'Test.IgnoreFailures'. - type: boolean - remediateLastFailure: - description: |- - RemediateLastFailure tells the controller to remediate the last failure, when - no retries remain. Defaults to 'false' unless 'Retries' is greater than 0. - type: boolean - retries: - description: |- - Retries is the number of retries that should be attempted on failures before - bailing. Remediation, using 'Strategy', is performed between each attempt. - Defaults to '0', a negative integer equals to unlimited retries. - type: integer - strategy: - description: - Strategy to use for failure remediation. Defaults - to 'rollback'. - enum: - - rollback - - uninstall - type: string - type: object - timeout: - description: |- - Timeout is the time to wait for any individual Kubernetes operation (like - Jobs for hooks) during the performance of a Helm upgrade action. Defaults to - 'HelmReleaseSpec.Timeout'. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - type: object - values: - description: Values holds the values for this Helm release. - x-kubernetes-preserve-unknown-fields: true - valuesFrom: - description: |- - ValuesFrom holds references to resources containing Helm values for this HelmRelease, - and information about how they should be merged. - items: - description: |- - ValuesReference contains a reference to a resource containing Helm values, - and optionally the key they can be found at. - properties: - kind: - description: - Kind of the values referent, valid values are ('Secret', - 'ConfigMap'). - enum: - - Secret - - ConfigMap - type: string - name: - description: |- - Name of the values referent. Should reside in the same namespace as the - referring resource. - maxLength: 253 - minLength: 1 - type: string - optional: - description: |- - Optional marks this ValuesReference as optional. When set, a not found error - for the values reference is ignored, but any ValuesKey, TargetPath or - transient error will still result in a reconciliation failure. - type: boolean - targetPath: - description: |- - TargetPath is the YAML dot notation path the value should be merged at. When - set, the ValuesKey is expected to be a single flat value. Defaults to 'None', - which results in the values getting merged at the root. - maxLength: 250 - pattern: ^([a-zA-Z0-9_\-.\\\/]|\[[0-9]{1,5}\])+$ - type: string - valuesKey: - description: |- - ValuesKey is the data key where the values.yaml or a specific value can be - found at. Defaults to 'values.yaml'. - maxLength: 253 - pattern: ^[\-._a-zA-Z0-9]+$ - type: string - required: - - kind - - name - type: object - type: array - required: - - interval - type: object - x-kubernetes-validations: - - message: either chart or chartRef must be set - rule: - (has(self.chart) && !has(self.chartRef)) || (!has(self.chart) - && has(self.chartRef)) - status: - default: - observedGeneration: -1 - description: HelmReleaseStatus defines the observed state of a HelmRelease. - properties: - conditions: - description: Conditions holds the conditions for the HelmRelease. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - failures: - description: |- - Failures is the reconciliation failure count against the latest desired - state. It is reset after a successful reconciliation. - format: int64 - type: integer - helmChart: - description: |- - HelmChart is the namespaced name of the HelmChart resource created by - the controller for the HelmRelease. - type: string - history: - description: |- - History holds the history of Helm releases performed for this HelmRelease - up to the last successfully completed release. - items: - description: |- - Snapshot captures a point-in-time copy of the status information for a Helm release, - as managed by the controller. - properties: - apiVersion: - description: |- - APIVersion is the API version of the Snapshot. - Provisional: when the calculation method of the Digest field is changed, - this field will be used to distinguish between the old and new methods. - type: string - appVersion: - description: - AppVersion is the chart app version of the release - object in storage. - type: string - chartName: - description: - ChartName is the chart name of the release object - in storage. - type: string - chartVersion: - description: |- - ChartVersion is the chart version of the release object in - storage. - type: string - configDigest: - description: |- - ConfigDigest is the checksum of the config (better known as - "values") of the release object in storage. - It has the format of `:`. - type: string - deleted: - description: Deleted is when the release was deleted. - format: date-time - type: string - digest: - description: |- - Digest is the checksum of the release object in storage. - It has the format of `:`. - type: string - firstDeployed: - description: FirstDeployed is when the release was first deployed. - format: date-time - type: string - lastDeployed: - description: LastDeployed is when the release was last deployed. - format: date-time - type: string - name: - description: Name is the name of the release. - type: string - namespace: - description: - Namespace is the namespace the release is deployed - to. - type: string - ociDigest: - description: - OCIDigest is the digest of the OCI artifact associated - with the release. - type: string - status: - description: Status is the current state of the release. - type: string - testHooks: - additionalProperties: - description: |- - TestHookStatus holds the status information for a test hook as observed - to be run by the controller. - properties: - lastCompleted: - description: - LastCompleted is the time the test hook last - completed. - format: date-time - type: string - lastStarted: - description: - LastStarted is the time the test hook was - last started. - format: date-time - type: string - phase: - description: Phase the test hook was observed to be in. - type: string - type: object - description: |- - TestHooks is the list of test hooks for the release as observed to be - run by the controller. - type: object - version: - description: - Version is the version of the release object in - storage. - type: integer - required: - - chartName - - chartVersion - - configDigest - - digest - - firstDeployed - - lastDeployed - - name - - namespace - - status - - version - type: object - type: array - installFailures: - description: |- - InstallFailures is the install failure count against the latest desired - state. It is reset after a successful reconciliation. - format: int64 - type: integer - lastAppliedRevision: - description: |- - LastAppliedRevision is the revision of the last successfully applied - source. - Deprecated: the revision can now be found in the History. - type: string - lastAttemptedConfigDigest: - description: |- - LastAttemptedConfigDigest is the digest for the config (better known as - "values") of the last reconciliation attempt. - type: string - lastAttemptedGeneration: - description: |- - LastAttemptedGeneration is the last generation the controller attempted - to reconcile. - format: int64 - type: integer - lastAttemptedReleaseAction: - description: |- - LastAttemptedReleaseAction is the last release action performed for this - HelmRelease. It is used to determine the active remediation strategy. - enum: - - install - - upgrade - type: string - lastAttemptedRevision: - description: |- - LastAttemptedRevision is the Source revision of the last reconciliation - attempt. For OCIRepository sources, the 12 first characters of the digest are - appended to the chart version e.g. "1.2.3+1234567890ab". - type: string - lastAttemptedRevisionDigest: - description: |- - LastAttemptedRevisionDigest is the digest of the last reconciliation attempt. - This is only set for OCIRepository sources. - type: string - lastAttemptedValuesChecksum: - description: |- - LastAttemptedValuesChecksum is the SHA1 checksum for the values of the last - reconciliation attempt. - Deprecated: Use LastAttemptedConfigDigest instead. - type: string - lastHandledForceAt: - description: |- - LastHandledForceAt holds the value of the most recent force request - value, so a change of the annotation value can be detected. - type: string - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - lastHandledResetAt: - description: |- - LastHandledResetAt holds the value of the most recent reset request - value, so a change of the annotation value can be detected. - type: string - lastReleaseRevision: - description: |- - LastReleaseRevision is the revision of the last successful Helm release. - Deprecated: Use History instead. - type: integer - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - observedPostRenderersDigest: - description: |- - ObservedPostRenderersDigest is the digest for the post-renderers of - the last successful reconciliation attempt. - type: string - storageNamespace: - description: |- - StorageNamespace is the namespace of the Helm release storage for the - current release. - maxLength: 63 - minLength: 1 - type: string - upgradeFailures: - description: |- - UpgradeFailures is the upgrade failure count against the latest desired - state. It is reset after a successful reconciliation. - format: int64 - type: integer - type: object - type: object - served: true - storage: false - subresources: - status: {} ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - labels: - app.kubernetes.io/component: helm-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: helm-controller - namespace: flux-system ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - labels: - app.kubernetes.io/component: helm-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - control-plane: controller - name: helm-controller - namespace: flux-system -spec: - replicas: 1 - selector: - matchLabels: - app: helm-controller - template: - metadata: - annotations: - prometheus.io/port: "8080" - prometheus.io/scrape: "true" - labels: - app: helm-controller - spec: - containers: - - args: - - --events-addr=http://notification-controller.flux-system.svc.cluster.local./ - - --watch-all-namespaces=true - - --log-level=info - - --log-encoding=json - - --enable-leader-election - env: - - name: RUNTIME_NAMESPACE - valueFrom: - fieldRef: - fieldPath: metadata.namespace - - name: GOMAXPROCS - valueFrom: - resourceFieldRef: - containerName: manager - resource: limits.cpu - - name: GOMEMLIMIT - valueFrom: - resourceFieldRef: - containerName: manager - resource: limits.memory - image: ghcr.io/fluxcd/helm-controller:v1.2.0 - imagePullPolicy: IfNotPresent - livenessProbe: - httpGet: - path: /healthz - port: healthz - name: manager - ports: - - containerPort: 8080 - name: http-prom - protocol: TCP - - containerPort: 9440 - name: healthz - protocol: TCP - readinessProbe: - httpGet: - path: /readyz - port: healthz - resources: - limits: - cpu: 1000m - memory: 1Gi - requests: - cpu: 100m - memory: 64Mi - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - readOnlyRootFilesystem: true - runAsNonRoot: true - seccompProfile: - type: RuntimeDefault - volumeMounts: - - mountPath: /tmp - name: temp - nodeSelector: - kubernetes.io/os: linux - priorityClassName: system-cluster-critical - securityContext: - fsGroup: 1337 - serviceAccountName: helm-controller - terminationGracePeriodSeconds: 600 - volumes: - - emptyDir: {} - name: temp ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: notification-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: alerts.notification.toolkit.fluxcd.io -spec: - group: notification.toolkit.fluxcd.io - names: - kind: Alert - listKind: AlertList - plural: alerts - singular: alert - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta1 Alert is deprecated, upgrade to v1beta3 - name: v1beta1 - schema: - openAPIV3Schema: - description: Alert is the Schema for the alerts API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: - AlertSpec defines an alerting rule for events involving a - list of objects - properties: - eventSeverity: - default: info - description: |- - Filter events based on severity, defaults to ('info'). - If set to 'info' no events will be filtered. - enum: - - info - - error - type: string - eventSources: - description: Filter events based on the involved objects. - items: - description: |- - CrossNamespaceObjectReference contains enough information to let you locate the - typed referenced object at cluster level - properties: - apiVersion: - description: API version of the referent - type: string - kind: - description: Kind of the referent - enum: - - Bucket - - GitRepository - - Kustomization - - HelmRelease - - HelmChart - - HelmRepository - - ImageRepository - - ImagePolicy - - ImageUpdateAutomation - - OCIRepository - type: string - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - name: - description: Name of the referent - maxLength: 53 - minLength: 1 - type: string - namespace: - description: Namespace of the referent - maxLength: 53 - minLength: 1 - type: string - required: - - kind - - name - type: object - type: array - exclusionList: - description: - A list of Golang regular expressions to be used for excluding - messages. - items: - type: string - type: array - providerRef: - description: Send events using this provider. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - summary: - description: Short description of the impact and affected cluster. - type: string - suspend: - description: |- - This flag tells the controller to suspend subsequent events dispatching. - Defaults to false. - type: boolean - required: - - eventSources - - providerRef - type: object - status: - default: - observedGeneration: -1 - description: AlertStatus defines the observed state of Alert - properties: - conditions: - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta2 Alert is deprecated, upgrade to v1beta3 - name: v1beta2 - schema: - openAPIV3Schema: - description: Alert is the Schema for the alerts API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: - AlertSpec defines an alerting rule for events involving a - list of objects. - properties: - eventMetadata: - additionalProperties: - type: string - description: |- - EventMetadata is an optional field for adding metadata to events dispatched by the - controller. This can be used for enhancing the context of the event. If a field - would override one already present on the original event as generated by the emitter, - then the override doesn't happen, i.e. the original value is preserved, and an info - log is printed. - type: object - eventSeverity: - default: info - description: |- - EventSeverity specifies how to filter events based on severity. - If set to 'info' no events will be filtered. - enum: - - info - - error - type: string - eventSources: - description: |- - EventSources specifies how to filter events based - on the involved object kind, name and namespace. - items: - description: |- - CrossNamespaceObjectReference contains enough information to let you locate the - typed referenced object at cluster level - properties: - apiVersion: - description: API version of the referent - type: string - kind: - description: Kind of the referent - enum: - - Bucket - - GitRepository - - Kustomization - - HelmRelease - - HelmChart - - HelmRepository - - ImageRepository - - ImagePolicy - - ImageUpdateAutomation - - OCIRepository - type: string - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - MatchLabels requires the name to be set to `*`. - type: object - name: - description: |- - Name of the referent - If multiple resources are targeted `*` may be set. - maxLength: 53 - minLength: 1 - type: string - namespace: - description: Namespace of the referent - maxLength: 53 - minLength: 1 - type: string - required: - - kind - - name - type: object - type: array - exclusionList: - description: |- - ExclusionList specifies a list of Golang regular expressions - to be used for excluding messages. - items: - type: string - type: array - inclusionList: - description: |- - InclusionList specifies a list of Golang regular expressions - to be used for including messages. - items: - type: string - type: array - providerRef: - description: - ProviderRef specifies which Provider this Alert should - use. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - summary: - description: - Summary holds a short description of the impact and affected - cluster. - maxLength: 255 - type: string - suspend: - description: |- - Suspend tells the controller to suspend subsequent - events handling for this Alert. - type: boolean - required: - - eventSources - - providerRef - type: object - status: - default: - observedGeneration: -1 - description: AlertStatus defines the observed state of the Alert. - properties: - conditions: - description: Conditions holds the conditions for the Alert. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - name: v1beta3 - schema: - openAPIV3Schema: - description: Alert is the Schema for the alerts API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: - AlertSpec defines an alerting rule for events involving a - list of objects. - properties: - eventMetadata: - additionalProperties: - type: string - description: |- - EventMetadata is an optional field for adding metadata to events dispatched by the - controller. This can be used for enhancing the context of the event. If a field - would override one already present on the original event as generated by the emitter, - then the override doesn't happen, i.e. the original value is preserved, and an info - log is printed. - type: object - eventSeverity: - default: info - description: |- - EventSeverity specifies how to filter events based on severity. - If set to 'info' no events will be filtered. - enum: - - info - - error - type: string - eventSources: - description: |- - EventSources specifies how to filter events based - on the involved object kind, name and namespace. - items: - description: |- - CrossNamespaceObjectReference contains enough information to let you locate the - typed referenced object at cluster level - properties: - apiVersion: - description: API version of the referent - type: string - kind: - description: Kind of the referent - enum: - - Bucket - - GitRepository - - Kustomization - - HelmRelease - - HelmChart - - HelmRepository - - ImageRepository - - ImagePolicy - - ImageUpdateAutomation - - OCIRepository - type: string - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - MatchLabels requires the name to be set to `*`. - type: object - name: - description: |- - Name of the referent - If multiple resources are targeted `*` may be set. - maxLength: 53 - minLength: 1 - type: string - namespace: - description: Namespace of the referent - maxLength: 53 - minLength: 1 - type: string - required: - - kind - - name - type: object - type: array - exclusionList: - description: |- - ExclusionList specifies a list of Golang regular expressions - to be used for excluding messages. - items: - type: string - type: array - inclusionList: - description: |- - InclusionList specifies a list of Golang regular expressions - to be used for including messages. - items: - type: string - type: array - providerRef: - description: - ProviderRef specifies which Provider this Alert should - use. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - summary: - description: |- - Summary holds a short description of the impact and affected cluster. - Deprecated: Use EventMetadata instead. - maxLength: 255 - type: string - suspend: - description: |- - Suspend tells the controller to suspend subsequent - events handling for this Alert. - type: boolean - required: - - eventSources - - providerRef - type: object - type: object - served: true - storage: true - subresources: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: notification-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: providers.notification.toolkit.fluxcd.io -spec: - group: notification.toolkit.fluxcd.io - names: - kind: Provider - listKind: ProviderList - plural: providers - singular: provider - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta1 Provider is deprecated, upgrade to v1beta3 - name: v1beta1 - schema: - openAPIV3Schema: - description: Provider is the Schema for the providers API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: ProviderSpec defines the desired state of Provider - properties: - address: - description: HTTP/S webhook address of this provider - pattern: ^(http|https):// - type: string - certSecretRef: - description: |- - CertSecretRef can be given the name of a secret containing - a PEM-encoded CA certificate (`caFile`) - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - channel: - description: Alert channel for this provider - type: string - proxy: - description: HTTP/S address of the proxy - pattern: ^(http|https):// - type: string - secretRef: - description: |- - Secret reference containing the provider webhook URL - using "address" as data key - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - This flag tells the controller to suspend subsequent events handling. - Defaults to false. - type: boolean - timeout: - description: Timeout for sending alerts to the provider. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - type: - description: Type of provider - enum: - - slack - - discord - - msteams - - rocket - - generic - - generic-hmac - - github - - gitlab - - bitbucket - - azuredevops - - googlechat - - webex - - sentry - - azureeventhub - - telegram - - lark - - matrix - - opsgenie - - alertmanager - - grafana - - githubdispatch - type: string - username: - description: Bot username for this provider - type: string - required: - - type - type: object - status: - default: - observedGeneration: -1 - description: ProviderStatus defines the observed state of Provider - properties: - conditions: - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - observedGeneration: - description: ObservedGeneration is the last reconciled generation. - format: int64 - type: integer - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta2 Provider is deprecated, upgrade to v1beta3 - name: v1beta2 - schema: - openAPIV3Schema: - description: Provider is the Schema for the providers API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: ProviderSpec defines the desired state of the Provider. - properties: - address: - description: |- - Address specifies the endpoint, in a generic sense, to where alerts are sent. - What kind of endpoint depends on the specific Provider type being used. - For the generic Provider, for example, this is an HTTP/S address. - For other Provider types this could be a project ID or a namespace. - maxLength: 2048 - type: string - certSecretRef: - description: |- - CertSecretRef specifies the Secret containing - a PEM-encoded CA certificate (in the `ca.crt` key). - - Note: Support for the `caFile` key has - been deprecated. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - channel: - description: - Channel specifies the destination channel where events - should be posted. - maxLength: 2048 - type: string - interval: - description: - Interval at which to reconcile the Provider with its - Secret references. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - proxy: - description: Proxy the HTTP/S address of the proxy server. - maxLength: 2048 - pattern: ^(http|https)://.*$ - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing the authentication - credentials for this Provider. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend subsequent - events handling for this Provider. - type: boolean - timeout: - description: Timeout for sending alerts to the Provider. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - type: - description: Type specifies which Provider implementation to use. - enum: - - slack - - discord - - msteams - - rocket - - generic - - generic-hmac - - github - - gitlab - - gitea - - bitbucketserver - - bitbucket - - azuredevops - - googlechat - - googlepubsub - - webex - - sentry - - azureeventhub - - telegram - - lark - - matrix - - opsgenie - - alertmanager - - grafana - - githubdispatch - - pagerduty - - datadog - type: string - username: - description: Username specifies the name under which events are posted. - maxLength: 2048 - type: string - required: - - type - type: object - status: - default: - observedGeneration: -1 - description: ProviderStatus defines the observed state of the Provider. - properties: - conditions: - description: Conditions holds the conditions for the Provider. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: ObservedGeneration is the last reconciled generation. - format: int64 - type: integer - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - name: v1beta3 - schema: - openAPIV3Schema: - description: Provider is the Schema for the providers API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: ProviderSpec defines the desired state of the Provider. - properties: - address: - description: |- - Address specifies the endpoint, in a generic sense, to where alerts are sent. - What kind of endpoint depends on the specific Provider type being used. - For the generic Provider, for example, this is an HTTP/S address. - For other Provider types this could be a project ID or a namespace. - maxLength: 2048 - type: string - certSecretRef: - description: |- - CertSecretRef specifies the Secret containing - a PEM-encoded CA certificate (in the `ca.crt` key). - - Note: Support for the `caFile` key has - been deprecated. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - channel: - description: - Channel specifies the destination channel where events - should be posted. - maxLength: 2048 - type: string - interval: - description: |- - Interval at which to reconcile the Provider with its Secret references. - Deprecated and not used in v1beta3. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - proxy: - description: Proxy the HTTP/S address of the proxy server. - maxLength: 2048 - pattern: ^(http|https)://.*$ - type: string - secretRef: - description: |- - SecretRef specifies the Secret containing the authentication - credentials for this Provider. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend subsequent - events handling for this Provider. - type: boolean - timeout: - description: Timeout for sending alerts to the Provider. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$ - type: string - type: - description: Type specifies which Provider implementation to use. - enum: - - slack - - discord - - msteams - - rocket - - generic - - generic-hmac - - github - - gitlab - - gitea - - bitbucketserver - - bitbucket - - azuredevops - - googlechat - - googlepubsub - - webex - - sentry - - azureeventhub - - telegram - - lark - - matrix - - opsgenie - - alertmanager - - grafana - - githubdispatch - - pagerduty - - datadog - - nats - type: string - username: - description: Username specifies the name under which events are posted. - maxLength: 2048 - type: string - required: - - type - type: object - type: object - served: true - storage: true - subresources: {} ---- -apiVersion: apiextensions.k8s.io/v1 -kind: CustomResourceDefinition -metadata: - annotations: - controller-gen.kubebuilder.io/version: v0.16.1 - labels: - app.kubernetes.io/component: notification-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: receivers.notification.toolkit.fluxcd.io -spec: - group: notification.toolkit.fluxcd.io - names: - kind: Receiver - listKind: ReceiverList - plural: receivers - singular: receiver - scope: Namespaced - versions: - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - name: v1 - schema: - openAPIV3Schema: - description: Receiver is the Schema for the receivers API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: ReceiverSpec defines the desired state of the Receiver. - properties: - events: - description: |- - Events specifies the list of event types to handle, - e.g. 'push' for GitHub or 'Push Hook' for GitLab. - items: - type: string - type: array - interval: - default: 10m - description: - Interval at which to reconcile the Receiver with its - Secret references. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - resourceFilter: - description: |- - ResourceFilter is a CEL expression expected to return a boolean that is - evaluated for each resource referenced in the Resources field when a - webhook is received. If the expression returns false then the controller - will not request a reconciliation for the resource. - When the expression is specified the controller will parse it and mark - the object as terminally failed if the expression is invalid or does not - return a boolean. - type: string - resources: - description: A list of resources to be notified about changes. - items: - description: |- - CrossNamespaceObjectReference contains enough information to let you locate the - typed referenced object at cluster level - properties: - apiVersion: - description: API version of the referent - type: string - kind: - description: Kind of the referent - enum: - - Bucket - - GitRepository - - Kustomization - - HelmRelease - - HelmChart - - HelmRepository - - ImageRepository - - ImagePolicy - - ImageUpdateAutomation - - OCIRepository - type: string - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - MatchLabels requires the name to be set to `*`. - type: object - name: - description: |- - Name of the referent - If multiple resources are targeted `*` may be set. - maxLength: 53 - minLength: 1 - type: string - namespace: - description: Namespace of the referent - maxLength: 53 - minLength: 1 - type: string - required: - - kind - - name - type: object - type: array - secretRef: - description: |- - SecretRef specifies the Secret containing the token used - to validate the payload authenticity. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend subsequent - events handling for this receiver. - type: boolean - type: - description: |- - Type of webhook sender, used to determine - the validation procedure and payload deserialization. - enum: - - generic - - generic-hmac - - github - - gitlab - - bitbucket - - harbor - - dockerhub - - quay - - gcr - - nexus - - acr - - cdevents - type: string - required: - - resources - - secretRef - - type - type: object - status: - default: - observedGeneration: -1 - description: ReceiverStatus defines the observed state of the Receiver. - properties: - conditions: - description: Conditions holds the conditions for the Receiver. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: - ObservedGeneration is the last observed generation of - the Receiver object. - format: int64 - type: integer - webhookPath: - description: |- - WebhookPath is the generated incoming webhook address in the format - of '/hook/sha256sum(token+name+namespace)'. - type: string - type: object - type: object - served: true - storage: true - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta1 Receiver is deprecated, upgrade to v1 - name: v1beta1 - schema: - openAPIV3Schema: - description: Receiver is the Schema for the receivers API - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: ReceiverSpec defines the desired state of Receiver - properties: - events: - description: |- - A list of events to handle, - e.g. 'push' for GitHub or 'Push Hook' for GitLab. - items: - type: string - type: array - resources: - description: A list of resources to be notified about changes. - items: - description: |- - CrossNamespaceObjectReference contains enough information to let you locate the - typed referenced object at cluster level - properties: - apiVersion: - description: API version of the referent - type: string - kind: - description: Kind of the referent - enum: - - Bucket - - GitRepository - - Kustomization - - HelmRelease - - HelmChart - - HelmRepository - - ImageRepository - - ImagePolicy - - ImageUpdateAutomation - - OCIRepository - type: string - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - type: object - name: - description: Name of the referent - maxLength: 53 - minLength: 1 - type: string - namespace: - description: Namespace of the referent - maxLength: 53 - minLength: 1 - type: string - required: - - kind - - name - type: object - type: array - secretRef: - description: |- - Secret reference containing the token used - to validate the payload authenticity - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - This flag tells the controller to suspend subsequent events handling. - Defaults to false. - type: boolean - type: - description: |- - Type of webhook sender, used to determine - the validation procedure and payload deserialization. - enum: - - generic - - generic-hmac - - github - - gitlab - - bitbucket - - harbor - - dockerhub - - quay - - gcr - - nexus - - acr - type: string - required: - - resources - - secretRef - - type - type: object - status: - default: - observedGeneration: -1 - description: ReceiverStatus defines the observed state of Receiver - properties: - conditions: - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - observedGeneration: - description: ObservedGeneration is the last observed generation. - format: int64 - type: integer - url: - description: |- - Generated webhook URL in the format - of '/hook/sha256sum(token+name+namespace)'. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} - - additionalPrinterColumns: - - jsonPath: .metadata.creationTimestamp - name: Age - type: date - - jsonPath: .status.conditions[?(@.type=="Ready")].status - name: Ready - type: string - - jsonPath: .status.conditions[?(@.type=="Ready")].message - name: Status - type: string - deprecated: true - deprecationWarning: v1beta2 Receiver is deprecated, upgrade to v1 - name: v1beta2 - schema: - openAPIV3Schema: - description: Receiver is the Schema for the receivers API. - properties: - apiVersion: - description: |- - APIVersion defines the versioned schema of this representation of an object. - Servers should convert recognized schemas to the latest internal value, and - may reject unrecognized values. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources - type: string - kind: - description: |- - Kind is a string value representing the REST resource this object represents. - Servers may infer this from the endpoint the client submits requests to. - Cannot be updated. - In CamelCase. - More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds - type: string - metadata: - type: object - spec: - description: ReceiverSpec defines the desired state of the Receiver. - properties: - events: - description: |- - Events specifies the list of event types to handle, - e.g. 'push' for GitHub or 'Push Hook' for GitLab. - items: - type: string - type: array - interval: - description: - Interval at which to reconcile the Receiver with its - Secret references. - pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ - type: string - resources: - description: A list of resources to be notified about changes. - items: - description: |- - CrossNamespaceObjectReference contains enough information to let you locate the - typed referenced object at cluster level - properties: - apiVersion: - description: API version of the referent - type: string - kind: - description: Kind of the referent - enum: - - Bucket - - GitRepository - - Kustomization - - HelmRelease - - HelmChart - - HelmRepository - - ImageRepository - - ImagePolicy - - ImageUpdateAutomation - - OCIRepository - type: string - matchLabels: - additionalProperties: - type: string - description: |- - MatchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels - map is equivalent to an element of matchExpressions, whose key field is "key", the - operator is "In", and the values array contains only "value". The requirements are ANDed. - MatchLabels requires the name to be set to `*`. - type: object - name: - description: |- - Name of the referent - If multiple resources are targeted `*` may be set. - maxLength: 53 - minLength: 1 - type: string - namespace: - description: Namespace of the referent - maxLength: 53 - minLength: 1 - type: string - required: - - kind - - name - type: object - type: array - secretRef: - description: |- - SecretRef specifies the Secret containing the token used - to validate the payload authenticity. - properties: - name: - description: Name of the referent. - type: string - required: - - name - type: object - suspend: - description: |- - Suspend tells the controller to suspend subsequent - events handling for this receiver. - type: boolean - type: - description: |- - Type of webhook sender, used to determine - the validation procedure and payload deserialization. - enum: - - generic - - generic-hmac - - github - - gitlab - - bitbucket - - harbor - - dockerhub - - quay - - gcr - - nexus - - acr - type: string - required: - - resources - - secretRef - - type - type: object - status: - default: - observedGeneration: -1 - description: ReceiverStatus defines the observed state of the Receiver. - properties: - conditions: - description: Conditions holds the conditions for the Receiver. - items: - description: - Condition contains details for one aspect of the current - state of this API Resource. - properties: - lastTransitionTime: - description: |- - lastTransitionTime is the last time the condition transitioned from one status to another. - This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. - format: date-time - type: string - message: - description: |- - message is a human readable message indicating details about the transition. - This may be an empty string. - maxLength: 32768 - type: string - observedGeneration: - description: |- - observedGeneration represents the .metadata.generation that the condition was set based upon. - For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date - with respect to the current state of the instance. - format: int64 - minimum: 0 - type: integer - reason: - description: |- - reason contains a programmatic identifier indicating the reason for the condition's last transition. - Producers of specific condition types may define expected values and meanings for this field, - and whether the values are considered a guaranteed API. - The value should be a CamelCase string. - This field may not be empty. - maxLength: 1024 - minLength: 1 - pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ - type: string - status: - description: status of the condition, one of True, False, Unknown. - enum: - - "True" - - "False" - - Unknown - type: string - type: - description: type of condition in CamelCase or in foo.example.com/CamelCase. - maxLength: 316 - pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ - type: string - required: - - lastTransitionTime - - message - - reason - - status - - type - type: object - type: array - lastHandledReconcileAt: - description: |- - LastHandledReconcileAt holds the value of the most recent - reconcile request value, so a change of the annotation value - can be detected. - type: string - observedGeneration: - description: - ObservedGeneration is the last observed generation of - the Receiver object. - format: int64 - type: integer - url: - description: |- - URL is the generated incoming webhook address in the format - of '/hook/sha256sum(token+name+namespace)'. - Deprecated: Replaced by WebhookPath. - type: string - webhookPath: - description: |- - WebhookPath is the generated incoming webhook address in the format - of '/hook/sha256sum(token+name+namespace)'. - type: string - type: object - type: object - served: true - storage: false - subresources: - status: {} ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - labels: - app.kubernetes.io/component: notification-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - name: notification-controller - namespace: flux-system ---- -apiVersion: v1 -kind: Service -metadata: - labels: - app.kubernetes.io/component: notification-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - control-plane: controller - name: notification-controller - namespace: flux-system -spec: - ports: - - name: http - port: 80 - protocol: TCP - targetPort: http - selector: - app: notification-controller - type: ClusterIP ---- -apiVersion: v1 -kind: Service -metadata: - labels: - app.kubernetes.io/component: notification-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - control-plane: controller - name: webhook-receiver - namespace: flux-system -spec: - ports: - - name: http - port: 80 - protocol: TCP - targetPort: http-webhook - selector: - app: notification-controller - type: ClusterIP ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - labels: - app.kubernetes.io/component: notification-controller - app.kubernetes.io/instance: flux-system - app.kubernetes.io/part-of: flux - app.kubernetes.io/version: v2.5.1 - control-plane: controller - name: notification-controller - namespace: flux-system -spec: - replicas: 1 - selector: - matchLabels: - app: notification-controller - template: - metadata: - annotations: - prometheus.io/port: "8080" - prometheus.io/scrape: "true" - labels: - app: notification-controller - spec: - containers: - - args: - - --watch-all-namespaces=true - - --log-level=info - - --log-encoding=json - - --enable-leader-election - env: - - name: RUNTIME_NAMESPACE - valueFrom: - fieldRef: - fieldPath: metadata.namespace - - name: GOMAXPROCS - valueFrom: - resourceFieldRef: - containerName: manager - resource: limits.cpu - - name: GOMEMLIMIT - valueFrom: - resourceFieldRef: - containerName: manager - resource: limits.memory - image: ghcr.io/fluxcd/notification-controller:v1.5.0 - imagePullPolicy: IfNotPresent - livenessProbe: - httpGet: - path: /healthz - port: healthz - name: manager - ports: - - containerPort: 9090 - name: http - protocol: TCP - - containerPort: 9292 - name: http-webhook - protocol: TCP - - containerPort: 8080 - name: http-prom - protocol: TCP - - containerPort: 9440 - name: healthz - protocol: TCP - readinessProbe: - httpGet: - path: /readyz - port: healthz - resources: - limits: - cpu: 1000m - memory: 1Gi - requests: - cpu: 100m - memory: 64Mi - securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL - readOnlyRootFilesystem: true - runAsNonRoot: true - seccompProfile: - type: RuntimeDefault - volumeMounts: - - mountPath: /tmp - name: temp - nodeSelector: - kubernetes.io/os: linux - securityContext: - fsGroup: 1337 - serviceAccountName: notification-controller - terminationGracePeriodSeconds: 10 - volumes: - - emptyDir: {} - name: temp diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index 303626c..06cad2e 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -8,6 +8,11 @@ let cfg = config.greg.kubernetes; cert-manager = pkgs.fetchurl { url = "https://github.com/cert-manager/cert-manager/releases/download/v1.18.2/cert-manager.yaml"; + sha256 = "0vx1nfyhl0rzb6psfxplq8pfp18mrrdk83n8rj2ph8q6r15vcih5"; + }; + flux = pkgs.fetchurl { + url = "https://github.com/fluxcd/flux2/releases/download/v2.5.1/install.yaml"; + sha256 = "1cjpxfgnzycwnac58gd3naxgmwsj5bdrx0vzh56aiq1m5c0h3dhs"; }; in { @@ -86,6 +91,7 @@ in ]; manifests = { cert-manager.source = cert-manager; + flux.source = flux; node-annotations.content = ../../manifests/nodes.yaml; }; role = if cfg.agentOnly then "agent" else "server"; From c6b96642f7c0bec1d7b2f5b195906bf02f231ee1 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 5 Sep 2025 13:49:18 -0500 Subject: [PATCH 094/124] Auto-install kyverno chart --- manifests/apply.sh | 2 -- manifests/helm/kustomization.yaml | 2 -- manifests/helm/kyverno.yaml | 40 ------------------------------- modules/nixos/kubernetes.nix | 17 +++++++++++++ 4 files changed, 17 insertions(+), 44 deletions(-) delete mode 100644 manifests/helm/kyverno.yaml diff --git a/manifests/apply.sh b/manifests/apply.sh index 7ffe584..6d0514d 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -6,8 +6,6 @@ SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )" # Change to the script directory cd "$SCRIPT_DIR" -kubectl apply -f helm/kyverno.yaml -sleep 15 kubectl apply -k helm sleep 5 # https://cloudnative-pg.io diff --git a/manifests/helm/kustomization.yaml b/manifests/helm/kustomization.yaml index 531baaf..fa4d303 100644 --- a/manifests/helm/kustomization.yaml +++ b/manifests/helm/kustomization.yaml @@ -1,6 +1,4 @@ resources: - - flux.yaml - - kyverno.yaml # Needed to configure Longhorn - longhorn.yaml # Needed for storage - traefik.yaml - external-secrets.yaml diff --git a/manifests/helm/kyverno.yaml b/manifests/helm/kyverno.yaml deleted file mode 100644 index bce3318..0000000 --- a/manifests/helm/kyverno.yaml +++ /dev/null @@ -1,40 +0,0 @@ -apiVersion: v1 -kind: Namespace -metadata: - name: kyverno-system ---- -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository -metadata: - name: kyverno - namespace: kyverno-system -spec: - interval: "24h" - url: "https://kyverno.github.io/kyverno/" ---- -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: kyverno - namespace: kyverno-system -spec: - interval: 10m - chart: - spec: - chart: kyverno - version: "3.4.4" - sourceRef: - kind: HelmRepository - name: kyverno - interval: "1h" - values: - admissionController: - replicas: 3 - backgroundController: - replicas: 3 - cleanupController: - replicas: 2 - reportsController: - replicas: 2 - crds: - install: true diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index 06cad2e..43d1527 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -78,6 +78,23 @@ in services = { k3s = { enable = true; + autoDeployCharts = { + kyverno = { + enable = true; + createNamespace = true; + name = "kyverno"; + repo = "https://kyverno.github.io/kyverno/"; + targetNamespace = "kyverno-system"; + values = { + admissionController.replicas = 3; + backgroundController.replicas = 3; + cleanupController.replicas = 2; + reportsController.replicas = 2; + crds.install = true; + }; + version = "3.4.4"; + }; + }; extraFlags = [ "--cluster-cidr=10.211.0.0/16" "--service-cidr=10.221.0.0/16" From 5992fa86c0fea5524d2fb9b8e0c3f84eb39e1347 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 5 Sep 2025 14:01:30 -0500 Subject: [PATCH 095/124] Add external-secrets to helm distributions --- manifests/helm/external-secrets.yaml | 33 ---------------------------- manifests/helm/kustomization.yaml | 1 - modules/nixos/kubernetes.nix | 14 ++++++++++++ 3 files changed, 14 insertions(+), 34 deletions(-) delete mode 100644 manifests/helm/external-secrets.yaml diff --git a/manifests/helm/external-secrets.yaml b/manifests/helm/external-secrets.yaml deleted file mode 100644 index 7287ccf..0000000 --- a/manifests/helm/external-secrets.yaml +++ /dev/null @@ -1,33 +0,0 @@ -apiVersion: v1 -kind: Namespace -metadata: - name: external-secrets ---- -apiVersion: source.toolkit.fluxcd.io/v1 -kind: HelmRepository -metadata: - name: external-secrets - namespace: external-secrets -spec: - interval: "24h" - url: "https://charts.external-secrets.io/" ---- -apiVersion: helm.toolkit.fluxcd.io/v2 -kind: HelmRelease -metadata: - name: external-secrets - namespace: external-secrets -spec: - interval: 10m - chart: - spec: - chart: external-secrets - version: "0.17.0" - sourceRef: - kind: HelmRepository - name: external-secrets - interval: "1h" - values: - crds: - create: true - includeCRDs: true diff --git a/manifests/helm/kustomization.yaml b/manifests/helm/kustomization.yaml index fa4d303..95912ed 100644 --- a/manifests/helm/kustomization.yaml +++ b/manifests/helm/kustomization.yaml @@ -1,4 +1,3 @@ resources: - longhorn.yaml # Needed for storage - traefik.yaml - - external-secrets.yaml diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index 43d1527..ae73896 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -79,9 +79,23 @@ in k3s = { enable = true; autoDeployCharts = { + external-secrets = { + enable = true; + createNamespace = true; + #hash = ""; + name = "external-secrets"; + repo = "https://charts.external-secrets.io/"; + targetNamespace = "external-secrets"; + values = { + crds.create = true; + includeCRDs = true; + }; + version = "0.17.0"; + }; kyverno = { enable = true; createNamespace = true; + #hash = ""; name = "kyverno"; repo = "https://kyverno.github.io/kyverno/"; targetNamespace = "kyverno-system"; From 52189eff579fea1bdbb4c8e3d76d46233c4cf685 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 5 Sep 2025 15:01:27 -0500 Subject: [PATCH 096/124] Use nixhelm repo, add tailscale to autodeploy --- flake.nix | 7 ++++++ manifests/apply.sh | 1 - manifests/secrets/operator-oauth.yaml | 33 +++++++++++++++++++++++++++ modules/nixos/kubernetes.nix | 19 ++++++++++----- 4 files changed, 53 insertions(+), 7 deletions(-) create mode 100644 manifests/secrets/operator-oauth.yaml diff --git a/flake.nix b/flake.nix index 0ee2160..4ad504c 100644 --- a/flake.nix +++ b/flake.nix @@ -21,6 +21,9 @@ btc = { url = "github:fort-nix/nix-bitcoin/release"; }; + charts = { + url = "github:nix-community/nixhelm"; + }; darwin = { url = "github:lnl7/nix-darwin/master"; inputs.nixpkgs.follows = "nixunstable"; @@ -63,8 +66,12 @@ pkgs = prev; }) ); + charts_overlay = ( + _f: _p: { inherit (top) chartsMetadata; } + ); overlays = [ top.agenix.overlays.default + charts_overlay local_overlay packages_overlay top.nurpkgs.overlays.default diff --git a/manifests/apply.sh b/manifests/apply.sh index 6d0514d..fd0a82e 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -16,7 +16,6 @@ helm upgrade --install cnpg \ -f values/cnpg.yaml \ --wait sleep 5 -./tailscale/apply.sh kubectl apply -k . ./immich/apply.sh diff --git a/manifests/secrets/operator-oauth.yaml b/manifests/secrets/operator-oauth.yaml new file mode 100644 index 0000000..ad60558 --- /dev/null +++ b/manifests/secrets/operator-oauth.yaml @@ -0,0 +1,33 @@ +apiVersion: external-secrets.io/v1 +kind: ExternalSecret +metadata: + name: operator-oauth + namespace: tailscale +spec: + target: + name: operator-oauth + deletionPolicy: Delete + template: + type: kubernetes.io/basic-auth + data: + username: |- + {{ .username }} + password: |- + {{ .password }} + data: + - secretKey: username + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: ffa188a4-63b2-4926-99f0-b33b0021a4f4 + property: username + - secretKey: password + sourceRef: + storeRef: + name: bitwarden-login + kind: ClusterSecretStore + remoteRef: + key: ffa188a4-63b2-4926-99f0-b33b0021a4f4 + property: password diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index ae73896..679f544 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -80,24 +80,23 @@ in enable = true; autoDeployCharts = { external-secrets = { + inherit (pkgs.chartsMetadata.external-secrets.external-secrets) repo version; enable = true; createNamespace = true; - #hash = ""; + hash = pkgs.chartsMetadata.external-secrets.external-secrets.chartHash; name = "external-secrets"; - repo = "https://charts.external-secrets.io/"; targetNamespace = "external-secrets"; values = { crds.create = true; includeCRDs = true; }; - version = "0.17.0"; }; kyverno = { + inherit (pkgs.chartsMetadata.kyverno.kyverno) repo version; enable = true; createNamespace = true; - #hash = ""; + hash = pkgs.chartsMetadata.kyverno.kyverno.chartHash; name = "kyverno"; - repo = "https://kyverno.github.io/kyverno/"; targetNamespace = "kyverno-system"; values = { admissionController.replicas = 3; @@ -106,7 +105,14 @@ in reportsController.replicas = 2; crds.install = true; }; - version = "3.4.4"; + }; + tailscale = { + inherit (pkgs.chartsMetadata.tailscale.tailscale-operator) repo version; + enable = true; + createNamespace = true; + hash = pkgs.chartsMetadata.tailscale.tailscale-operator.chartHash; + name = "tailscale-operator"; + targetNamespace = "tailscale"; }; }; extraFlags = [ @@ -124,6 +130,7 @@ in cert-manager.source = cert-manager; flux.source = flux; node-annotations.content = ../../manifests/nodes.yaml; + operator-oauth.content = ../../manifests/external-secrets/operator-oauth.yaml; }; role = if cfg.agentOnly then "agent" else "server"; serverAddr = lib.mkIf (config.networking.hostName != "isaiah") "https://isaiah.home:6443"; From 3b24d5ae26216df5599fdeaf781d6575b5c29aa5 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 5 Sep 2025 15:53:14 -0500 Subject: [PATCH 097/124] Cleanup external references --- flake.lock | 245 +++++++++++++++++++++++++++++++++-- flake.nix | 2 +- modules/nixos/kubernetes.nix | 4 +- 3 files changed, 238 insertions(+), 13 deletions(-) diff --git a/flake.lock b/flake.lock index d9dabec..9654303 100644 --- a/flake.lock +++ b/flake.lock @@ -45,6 +45,28 @@ "type": "github" } }, + "charts": { + "inputs": { + "flake-utils": "flake-utils_2", + "haumea": "haumea", + "nix-kube-generators": "nix-kube-generators", + "nixpkgs": "nixpkgs_2", + "poetry2nix": "poetry2nix" + }, + "locked": { + "lastModified": 1757035572, + "narHash": "sha256-GvI7osKYW7Rufa6WS361vwBAul+okcnI00ExNUtk950=", + "owner": "nix-community", + "repo": "nixhelm", + "rev": "8a7daca797bd0f488ff5e3b52f4faf913c90ec2e", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixhelm", + "type": "github" + } + }, "darwin": { "inputs": { "nixpkgs": [ @@ -251,13 +273,30 @@ "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", "type": "github" }, + "original": { + "id": "flake-utils", + "type": "indirect" + } + }, + "flake-utils_3": { + "inputs": { + "systems": "systems_4" + }, + "locked": { + "lastModified": 1726560853, + "narHash": "sha256-X6rJYSESBVr3hBoH0WbKE5KvhPU5bloyZ2L4K60/fPQ=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "c1dfcf08411b08f6b8615f7d8971a2bfa81d5e8a", + "type": "github" + }, "original": { "owner": "numtide", "repo": "flake-utils", "type": "github" } }, - "flake-utils_3": { + "flake-utils_4": { "inputs": { "systems": "systems_6" }, @@ -275,6 +314,24 @@ "type": "github" } }, + "flake-utils_5": { + "inputs": { + "systems": "systems_9" + }, + "locked": { + "lastModified": 1731533236, + "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "flake-utils", + "type": "github" + } + }, "gitignore": { "inputs": { "nixpkgs": [ @@ -296,6 +353,28 @@ "type": "github" } }, + "haumea": { + "inputs": { + "nixpkgs": [ + "charts", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1685133229, + "narHash": "sha256-FePm/Gi9PBSNwiDFq3N+DWdfxFq0UKsVVTJS3cQPn94=", + "owner": "nix-community", + "repo": "haumea", + "rev": "34dd58385092a23018748b50f9b23de6266dffc2", + "type": "github" + }, + "original": { + "owner": "nix-community", + "ref": "v0.2.2", + "repo": "haumea", + "type": "github" + } + }, "hmunstable": { "inputs": { "nixpkgs": [ @@ -342,7 +421,7 @@ "inputs": { "flake-compat": "flake-compat", "gitignore": "gitignore", - "nixpkgs": "nixpkgs_2" + "nixpkgs": "nixpkgs_3" }, "locked": { "lastModified": 1755446520, @@ -386,6 +465,28 @@ "type": "github" } }, + "nix-github-actions": { + "inputs": { + "nixpkgs": [ + "charts", + "poetry2nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1729742964, + "narHash": "sha256-B4mzTcQ0FZHdpeWcpDYPERtyjJd/NIuaQ9+BV1h+MpA=", + "owner": "nix-community", + "repo": "nix-github-actions", + "rev": "e04df33f62cdcf93d73e9a04142464753a16db67", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nix-github-actions", + "type": "github" + } + }, "nix-hardware": { "locked": { "lastModified": 1755330281, @@ -401,6 +502,21 @@ "type": "github" } }, + "nix-kube-generators": { + "locked": { + "lastModified": 1729269463, + "narHash": "sha256-8jDDpC99fYl5CSHjZyPwb5PK7nQSknhkpfe8+DXI910=", + "owner": "farcaller", + "repo": "nix-kube-generators", + "rev": "2be4f3cb99e179d9f94e6c8723862421437f8efb", + "type": "github" + }, + "original": { + "owner": "farcaller", + "repo": "nix-kube-generators", + "type": "github" + } + }, "nixlib": { "locked": { "lastModified": 1736643958, @@ -515,6 +631,22 @@ } }, "nixpkgs_2": { + "locked": { + "lastModified": 1739020877, + "narHash": "sha256-mIvECo/NNdJJ/bXjNqIh8yeoSjVLAuDuTUzAo7dzs8Y=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "a79cfe0ebd24952b580b1cf08cd906354996d547", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" + } + }, + "nixpkgs_3": { "locked": { "lastModified": 1754340878, "narHash": "sha256-lgmUyVQL9tSnvvIvBp7x1euhkkCho7n3TMzgjdvgPoU=", @@ -530,7 +662,7 @@ "type": "github" } }, - "nixpkgs_3": { + "nixpkgs_4": { "locked": { "lastModified": 1755186698, "narHash": "sha256-wNO3+Ks2jZJ4nTHMuks+cxAiVBGNuEBXsT29Bz6HASo=", @@ -546,7 +678,7 @@ "type": "github" } }, - "nixpkgs_4": { + "nixpkgs_5": { "locked": { "lastModified": 1744868846, "narHash": "sha256-5RJTdUHDmj12Qsv7XOhuospjAjATNiTMElplWnJE9Hs=", @@ -585,7 +717,7 @@ "nixunstable" ], "nuschtosSearch": "nuschtosSearch", - "systems": "systems_4" + "systems": "systems_7" }, "locked": { "lastModified": 1755095763, @@ -605,7 +737,7 @@ "nurpkgs": { "inputs": { "flake-parts": "flake-parts_3", - "nixpkgs": "nixpkgs_3" + "nixpkgs": "nixpkgs_4" }, "locked": { "lastModified": 1755452770, @@ -623,7 +755,7 @@ }, "nuschtosSearch": { "inputs": { - "flake-utils": "flake-utils_2", + "flake-utils": "flake-utils_4", "ixx": "ixx", "nixpkgs": [ "nixvimunstable", @@ -644,6 +776,31 @@ "type": "github" } }, + "poetry2nix": { + "inputs": { + "flake-utils": "flake-utils_3", + "nix-github-actions": "nix-github-actions", + "nixpkgs": [ + "charts", + "nixpkgs" + ], + "systems": "systems_5", + "treefmt-nix": "treefmt-nix" + }, + "locked": { + "lastModified": 1738741221, + "narHash": "sha256-UiTOA89yQV5YNlO1ZAp4IqJUGWOnTyBC83netvt8rQE=", + "owner": "nix-community", + "repo": "poetry2nix", + "rev": "be1fe795035d3d36359ca9135b26dcc5321b31fb", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "poetry2nix", + "type": "github" + } + }, "proxmox": { "inputs": { "flake-compat": "flake-compat_2", @@ -669,6 +826,7 @@ "inputs": { "agenix": "agenix", "btc": "btc", + "charts": "charts", "darwin": "darwin_2", "flake-parts": "flake-parts", "hmunstable": "hmunstable", @@ -773,9 +931,76 @@ "type": "github" } }, + "systems_7": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "systems_8": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "systems_9": { + "locked": { + "lastModified": 1681028828, + "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", + "owner": "nix-systems", + "repo": "default", + "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", + "type": "github" + }, + "original": { + "owner": "nix-systems", + "repo": "default", + "type": "github" + } + }, + "treefmt-nix": { + "inputs": { + "nixpkgs": [ + "charts", + "poetry2nix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1730120726, + "narHash": "sha256-LqHYIxMrl/1p3/kvm2ir925tZ8DkI0KA10djk8wecSk=", + "owner": "numtide", + "repo": "treefmt-nix", + "rev": "9ef337e492a5555d8e17a51c911ff1f02635be15", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "treefmt-nix", + "type": "github" + } + }, "utils": { "inputs": { - "systems": "systems_5" + "systems": "systems_8" }, "locked": { "lastModified": 1710146030, @@ -793,8 +1018,8 @@ }, "vsext": { "inputs": { - "flake-utils": "flake-utils_3", - "nixpkgs": "nixpkgs_4" + "flake-utils": "flake-utils_5", + "nixpkgs": "nixpkgs_5" }, "locked": { "lastModified": 1755396877, diff --git a/flake.nix b/flake.nix index 4ad504c..126e622 100644 --- a/flake.nix +++ b/flake.nix @@ -67,7 +67,7 @@ }) ); charts_overlay = ( - _f: _p: { inherit (top) chartsMetadata; } + _f: _p: { inherit (top.charts) chartsMetadata; } ); overlays = [ top.agenix.overlays.default diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index 679f544..0eba161 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -129,8 +129,8 @@ in manifests = { cert-manager.source = cert-manager; flux.source = flux; - node-annotations.content = ../../manifests/nodes.yaml; - operator-oauth.content = ../../manifests/external-secrets/operator-oauth.yaml; + node-annotations.source = ../../manifests/nodes.yaml; + operator-oauth.source = ../../manifests/secrets/operator-oauth.yaml; }; role = if cfg.agentOnly then "agent" else "server"; serverAddr = lib.mkIf (config.networking.hostName != "isaiah") "https://isaiah.home:6443"; From a7e0b32df4e33e7eef541cdb953d1ce54e546217 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 23:00:19 -0500 Subject: [PATCH 098/124] Make charts charty again --- flake.nix | 5 ++++- modules/nix-conf.nix | 2 ++ modules/nixos/kubernetes.nix | 22 ++++++++-------------- 3 files changed, 14 insertions(+), 15 deletions(-) diff --git a/flake.nix b/flake.nix index 126e622..5654219 100644 --- a/flake.nix +++ b/flake.nix @@ -67,7 +67,10 @@ }) ); charts_overlay = ( - _f: _p: { inherit (top.charts) chartsMetadata; } + _f: _p: { + chartsDerivations = top.charts.chartsDerivations."${_p.stdenv.hostPlatform.system}"; + kubelib = top.nix-kube-generators.lib; + } ); overlays = [ top.agenix.overlays.default diff --git a/modules/nix-conf.nix b/modules/nix-conf.nix index 0d5d7c8..c432e5c 100644 --- a/modules/nix-conf.nix +++ b/modules/nix-conf.nix @@ -49,6 +49,7 @@ in "https://greg-hellings.cachix.org" "https://nix-community.cachix.org" "https://cache.nixos.org" + "https://nixhelm.cachix.org" ]; trusted-public-keys = [ "chronicles.shire-zebra.ts.net:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8=" @@ -57,6 +58,7 @@ in "greg-hellings.cachix.org-1:y01Jl/L5evlhxdnUW6n56AiI1k8g1wxWhTxJCe7XSco=" "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" + "nixhelm.cachix.org-1:esqauAsR4opRF0UsGrA6H3gD21OrzMnBBYvJXeddjtY=" ]; }; }; diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index 0eba161..9e7d34f 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -80,11 +80,9 @@ in enable = true; autoDeployCharts = { external-secrets = { - inherit (pkgs.chartsMetadata.external-secrets.external-secrets) repo version; enable = true; createNamespace = true; - hash = pkgs.chartsMetadata.external-secrets.external-secrets.chartHash; - name = "external-secrets"; + package = pkgs.chartsDerivations.external-secrets.external-secrets; targetNamespace = "external-secrets"; values = { crds.create = true; @@ -92,26 +90,22 @@ in }; }; kyverno = { - inherit (pkgs.chartsMetadata.kyverno.kyverno) repo version; enable = true; createNamespace = true; - hash = pkgs.chartsMetadata.kyverno.kyverno.chartHash; - name = "kyverno"; + package = pkgs.chartsDerivations.kyverno.kyverno; targetNamespace = "kyverno-system"; values = { - admissionController.replicas = 3; - backgroundController.replicas = 3; - cleanupController.replicas = 2; - reportsController.replicas = 2; - crds.install = true; + admissionController.replicas = 3; + backgroundController.replicas = 3; + cleanupController.replicas = 2; + reportsController.replicas = 2; + crds.install = true; }; }; tailscale = { - inherit (pkgs.chartsMetadata.tailscale.tailscale-operator) repo version; enable = true; createNamespace = true; - hash = pkgs.chartsMetadata.tailscale.tailscale-operator.chartHash; - name = "tailscale-operator"; + package = pkgs.chartsDerivations.tailscale.tailscale-operator; targetNamespace = "tailscale"; }; }; From 251f333c3e0a073607ec4dcda8c67fd20c65af88 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 23:00:48 -0500 Subject: [PATCH 099/124] Change folder name for backups --- hosts/vm-gitlab/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hosts/vm-gitlab/default.nix b/hosts/vm-gitlab/default.nix index 8679bec..a7e5473 100644 --- a/hosts/vm-gitlab/default.nix +++ b/hosts/vm-gitlab/default.nix @@ -57,7 +57,7 @@ in backup.jobs.nas-backup = { src = "/var/gitlab/state/backup/"; dest = "gitlab"; - id = "container-gitlab"; + id = "gitlab"; }; home = true; tailscale.enable = true; From dd75f6cdd7f960f372f5aaf0c0f17c5bbe5d151c Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 23:01:00 -0500 Subject: [PATCH 100/124] Make output easier to read --- home/baseline/nushell/functions.nu | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/home/baseline/nushell/functions.nu b/home/baseline/nushell/functions.nu index 1660991..9affd65 100644 --- a/home/baseline/nushell/functions.nu +++ b/home/baseline/nushell/functions.nu @@ -32,7 +32,7 @@ def deploy [ $host: string, $build: string = "" ] { if $buildhost == "linode" { $buildhost = "isaiah" } - nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host $host --build-host $buildhost | complete + nixos-rebuild switch --sudo --use-substitutes --target-host $host --build-host $buildhost } def ff [ $file: string ] { @@ -40,5 +40,5 @@ def ff [ $file: string ] { } def update_all [] { - par-map $servers {|e| deploy $e} | explore + par-map $servers {|e| deploy $e | complete} | explore } From f326e92ca505bfe48f1e6f9d0347496752969b27 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 23:05:14 -0500 Subject: [PATCH 101/124] Fix yaml for longhorn --- manifests/helm/longhorn.yaml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/manifests/helm/longhorn.yaml b/manifests/helm/longhorn.yaml index 5f94899..b1a5fb7 100644 --- a/manifests/helm/longhorn.yaml +++ b/manifests/helm/longhorn.yaml @@ -30,12 +30,11 @@ spec: values: defaultSettings: createDefaultDiskLabeledNodes: true + # This should go back to null when I have more cluster + replicaSoftAntiAffinity: true persistence: # This should go back to 3 when I have more cluster defaultClassReplicaCount: 2 - defaultSettings: - # This should go back to null when I have more cluster - replicaSoftAntiAffinity: true --- apiVersion: v1 kind: ConfigMap From 9b4132610d2148a5e11adf2c8d190e02d8f3b9d5 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 23:39:08 -0500 Subject: [PATCH 102/124] Update gitlab-runner Helm chart --- manifests/gitlab-runner/chart.yaml | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/manifests/gitlab-runner/chart.yaml b/manifests/gitlab-runner/chart.yaml index 9421fff..578495d 100644 --- a/manifests/gitlab-runner/chart.yaml +++ b/manifests/gitlab-runner/chart.yaml @@ -15,7 +15,7 @@ spec: chart: spec: chart: gitlab-runner - version: "0.74.1" + version: "0.80.1" sourceRef: kind: HelmRepository name: gitlab-runner @@ -28,9 +28,11 @@ spec: runners: secret: gitlab-runner imagePullSecrets: - - image-pull-secrets + - name: image-pull-secrets rbac: create: true + serviceAccount: + create: true extraEnv: CACHE_TYPE: s3 CACHE_SHARED: "true" From c891c5f51495369ec44bc14085834921406906eb Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 23:57:10 -0500 Subject: [PATCH 103/124] Move some auto-deploy options around --- manifests/apply.sh | 1 + manifests/{ => auto}/nodes.yaml | 0 manifests/{secrets => auto}/operator-oauth.yaml | 0 manifests/tailscale/apply.sh | 2 -- modules/nixos/kubernetes.nix | 4 ++-- 5 files changed, 3 insertions(+), 4 deletions(-) rename manifests/{ => auto}/nodes.yaml (100%) rename manifests/{secrets => auto}/operator-oauth.yaml (100%) diff --git a/manifests/apply.sh b/manifests/apply.sh index fd0a82e..6200485 100755 --- a/manifests/apply.sh +++ b/manifests/apply.sh @@ -19,3 +19,4 @@ sleep 5 kubectl apply -k . ./immich/apply.sh +./tailscale/apply.sh diff --git a/manifests/nodes.yaml b/manifests/auto/nodes.yaml similarity index 100% rename from manifests/nodes.yaml rename to manifests/auto/nodes.yaml diff --git a/manifests/secrets/operator-oauth.yaml b/manifests/auto/operator-oauth.yaml similarity index 100% rename from manifests/secrets/operator-oauth.yaml rename to manifests/auto/operator-oauth.yaml diff --git a/manifests/tailscale/apply.sh b/manifests/tailscale/apply.sh index 5ecb10f..ce3307c 100755 --- a/manifests/tailscale/apply.sh +++ b/manifests/tailscale/apply.sh @@ -10,6 +10,4 @@ helm upgrade \ tailscale/tailscale-operator \ --namespace=tailscale \ --create-namespace \ - --set-string oauth.clientId="$(bw get username 'ffa188a4-63b2-4926-99f0-b33b0021a4f4')" \ - --set-string oauth.clientSecret="$(bw get password 'ffa188a4-63b2-4926-99f0-b33b0021a4f4')" \ --wait diff --git a/modules/nixos/kubernetes.nix b/modules/nixos/kubernetes.nix index 9e7d34f..e134470 100644 --- a/modules/nixos/kubernetes.nix +++ b/modules/nixos/kubernetes.nix @@ -123,8 +123,8 @@ in manifests = { cert-manager.source = cert-manager; flux.source = flux; - node-annotations.source = ../../manifests/nodes.yaml; - operator-oauth.source = ../../manifests/secrets/operator-oauth.yaml; + node-annotations.source = ../../manifests/auto/nodes.yaml; + operator-oauth.source = ../../manifests/auto/operator-oauth.yaml; }; role = if cfg.agentOnly then "agent" else "server"; serverAddr = lib.mkIf (config.networking.hostName != "isaiah") "https://isaiah.home:6443"; From e4732cd89c93a8e75929ef1a3fafa1b54efdf4b9 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Thu, 11 Sep 2025 23:59:50 -0500 Subject: [PATCH 104/124] Add README.md --- manifests/auto/README.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 manifests/auto/README.md diff --git a/manifests/auto/README.md b/manifests/auto/README.md new file mode 100644 index 0000000..53c65fa --- /dev/null +++ b/manifests/auto/README.md @@ -0,0 +1,12 @@ +It should not be necessary to deploy these files as, ostensibly, they are +configured to be auto-deployed on the nodes at startup time. + +nodes.yaml contains things like annotations for the nodes and other similar +hubub that makes the code deploy in a friendly manner. + +operator-oauth.yaml includes the secrets that need to be defined before the +tailscale operator can be deployed. But, of course, it also needs things like +the external-secrets helm chart before it is fully deployed in the proper +manner. There is a little bit of a chicken and egg type of problem here, but +if you just keep applying everyting, over and over, it will eventually be +installed and configured correctly. From 62a8d97be3b6a06d25572671c9a126caa48f9fcc Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 12 Sep 2025 09:57:05 -0500 Subject: [PATCH 105/124] Source before reference --- home/baseline/nushell.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/home/baseline/nushell.nix b/home/baseline/nushell.nix index 13cae03..a25f88c 100644 --- a/home/baseline/nushell.nix +++ b/home/baseline/nushell.nix @@ -38,6 +38,8 @@ in path add /run/current-system/sw/bin path add ${config.home.homeDirectory}/.nix-profile/bin + source ${./nushell/functions.nu} + def --env vpn [] { unlock let username = ^bw get username f7351f9c-b25b-4317-8352-affc00da4644 @@ -45,8 +47,6 @@ in let otp = ^bw get totp 10371487-7f40-4b08-9a45-b33e00de318b osascript ${vpn} $username $"($password)($otp)" } - - source ${./nushell/functions.nu} ''; settings = { buffer_editor = lib.getExe config.programs.nixvim.package; From 6748ca22a4d39103b24d73f7373270b90a655edb Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 12 Sep 2025 13:25:00 -0500 Subject: [PATCH 106/124] Add bake command --- home/baseline/nushell/functions.nu | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/home/baseline/nushell/functions.nu b/home/baseline/nushell/functions.nu index 9affd65..7619fe4 100644 --- a/home/baseline/nushell/functions.nu +++ b/home/baseline/nushell/functions.nu @@ -42,3 +42,13 @@ def ff [ $file: string ] { def update_all [] { par-map $servers {|e| deploy $e | complete} | explore } + +def bake [template: string] { + let copier = "~/.copier-templates" | path expand + if not ($copier | path exists) { + git clone srcpub:greg/copier-templates.git $copier + } + let srcdir = [$copier $template] | path join + print $srcdir + copier copy $srcdir . +} From 04486bdd263d76b49175aebbdcf7ee5090c8c900 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 12 Sep 2025 20:12:10 -0500 Subject: [PATCH 107/124] Cluster restored, so re-enabling replica anti-affinity --- manifests/helm/longhorn.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifests/helm/longhorn.yaml b/manifests/helm/longhorn.yaml index b1a5fb7..68fb046 100644 --- a/manifests/helm/longhorn.yaml +++ b/manifests/helm/longhorn.yaml @@ -31,7 +31,7 @@ spec: defaultSettings: createDefaultDiskLabeledNodes: true # This should go back to null when I have more cluster - replicaSoftAntiAffinity: true + replicaSoftAntiAffinity: null persistence: # This should go back to 3 when I have more cluster defaultClassReplicaCount: 2 From 6d2b47d8b71b543c2cf4493eb650b6576e0bf9eb Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 15 Sep 2025 22:20:53 -0400 Subject: [PATCH 108/124] Add helm to home-manager --- home/baseline/tools.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index a653304..fa54b02 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -6,6 +6,7 @@ dig dnsutils jqp + kubernetes-helm iamb rainfrog tenere From d100f804df7f4e12d70c51de9852798c08e45ea6 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 16 Sep 2025 09:51:33 -0500 Subject: [PATCH 109/124] Update lock and add lazyssh --- flake.lock | 116 ++++++++++++++++++++-------------------- home/baseline/shell.nix | 2 +- home/baseline/tools.nix | 2 +- 3 files changed, 60 insertions(+), 60 deletions(-) diff --git a/flake.lock b/flake.lock index 9654303..d56ebce 100644 --- a/flake.lock +++ b/flake.lock @@ -31,11 +31,11 @@ "nixpkgs-unstable": "nixpkgs-unstable" }, "locked": { - "lastModified": 1753079037, - "narHash": "sha256-c1MvgF+0dU75CmowEAez8oC+M9dtXZ5WKfDZzuFTkP0=", + "lastModified": 1757876184, + "narHash": "sha256-ezKJm8vzMb6bZf2lG+/s4AGhXtMvshEYBYqDT2PLtIU=", "owner": "fort-nix", "repo": "nix-bitcoin", - "rev": "5031e254696c72f36a7e41ddf70dacdf6bd83e46", + "rev": "0c961fa789d69ccd9503d2548dca1a9285acf2ff", "type": "github" }, "original": { @@ -54,11 +54,11 @@ "poetry2nix": "poetry2nix" }, "locked": { - "lastModified": 1757035572, - "narHash": "sha256-GvI7osKYW7Rufa6WS361vwBAul+okcnI00ExNUtk950=", + "lastModified": 1757985998, + "narHash": "sha256-9wxH9I7BJflSBXxXQJwqqWLC/lGr96MNI++Ci70HBF0=", "owner": "nix-community", "repo": "nixhelm", - "rev": "8a7daca797bd0f488ff5e3b52f4faf913c90ec2e", + "rev": "0b9e8a1e3ed75731507d1055a75343a616dda286", "type": "github" }, "original": { @@ -96,11 +96,11 @@ ] }, "locked": { - "lastModified": 1755275010, - "narHash": "sha256-lEApCoWUEWh0Ifc3k1JdVjpMtFFXeL2gG1qvBnoRc2I=", + "lastModified": 1757430124, + "narHash": "sha256-MhDltfXesGH8VkGv3hmJ1QEKl1ChTIj9wmGAFfWj/Wk=", "owner": "lnl7", "repo": "nix-darwin", - "rev": "7220b01d679e93ede8d7b25d6f392855b81dd475", + "rev": "830b3f0b50045cf0bcfd4dab65fad05bf882e196", "type": "github" }, "original": { @@ -188,11 +188,11 @@ "nixpkgs-lib": "nixpkgs-lib" }, "locked": { - "lastModified": 1754487366, - "narHash": "sha256-pHYj8gUBapuUzKV/kN/tR3Zvqc7o6gdFB9XKXIp1SQ8=", + "lastModified": 1756770412, + "narHash": "sha256-+uWLQZccFHwqpGqr2Yt5VsW/PbeJVTn9Dk6SHWhNRPw=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "af66ad14b28a127c5c0f3bbb298218fc63528a18", + "rev": "4524271976b625a4a605beefd893f270620fd751", "type": "github" }, "original": { @@ -209,11 +209,11 @@ ] }, "locked": { - "lastModified": 1754487366, - "narHash": "sha256-pHYj8gUBapuUzKV/kN/tR3Zvqc7o6gdFB9XKXIp1SQ8=", + "lastModified": 1756770412, + "narHash": "sha256-+uWLQZccFHwqpGqr2Yt5VsW/PbeJVTn9Dk6SHWhNRPw=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "af66ad14b28a127c5c0f3bbb298218fc63528a18", + "rev": "4524271976b625a4a605beefd893f270620fd751", "type": "github" }, "original": { @@ -382,11 +382,11 @@ ] }, "locked": { - "lastModified": 1755442500, - "narHash": "sha256-RHK4H6SWzkAtW/5WBHsyugaXJX25yr5y7FAZznxcBJs=", + "lastModified": 1757997814, + "narHash": "sha256-F+1aoG+3NH4jDDEmhnDUReISyq6kQBBuktTUqCUWSiw=", "owner": "nix-community", "repo": "home-manager", - "rev": "d2ffdedfc39c591367b1ddf22b4ce107f029dcc3", + "rev": "5820376beb804de9acf07debaaff1ac84728b708", "type": "github" }, "original": { @@ -424,11 +424,11 @@ "nixpkgs": "nixpkgs_3" }, "locked": { - "lastModified": 1755446520, - "narHash": "sha256-I0Ok1OGDwc1jPd8cs2VvAYZsHriUVFGIUqW+7uSsOUM=", + "lastModified": 1757974173, + "narHash": "sha256-4DpXmct/2rcLgScT1CXOLr0TUeIlrBB1rnFqCOf5MUw=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "4b04db83821b819bbbe32ed0a025b31e7971f22e", + "rev": "302af509428169db34f268324162712d10559f74", "type": "github" }, "original": { @@ -451,16 +451,16 @@ ] }, "locked": { - "lastModified": 1748294338, - "narHash": "sha256-FVO01jdmUNArzBS7NmaktLdGA5qA3lUMJ4B7a05Iynw=", + "lastModified": 1754860581, + "narHash": "sha256-EM0IE63OHxXCOpDHXaTyHIOk2cNvMCGPqLt/IdtVxgk=", "owner": "NuschtOS", "repo": "ixx", - "rev": "cc5f390f7caf265461d4aab37e98d2292ebbdb85", + "rev": "babfe85a876162c4acc9ab6fb4483df88fa1f281", "type": "github" }, "original": { "owner": "NuschtOS", - "ref": "v0.0.8", + "ref": "v0.1.1", "repo": "ixx", "type": "github" } @@ -489,11 +489,11 @@ }, "nix-hardware": { "locked": { - "lastModified": 1755330281, - "narHash": "sha256-aJHFJWP9AuI8jUGzI77LYcSlkA9wJnOIg4ZqftwNGXA=", + "lastModified": 1757943327, + "narHash": "sha256-w6cDExPBqbq7fTLo4dZ1ozDGeq3yV6dSN4n/sAaS6OM=", "owner": "nixos", "repo": "nixos-hardware", - "rev": "3dac8a872557e0ca8c083cdcfc2f218d18e113b0", + "rev": "67a709cfe5d0643dafd798b0b613ed579de8be05", "type": "github" }, "original": { @@ -555,11 +555,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1752866191, - "narHash": "sha256-NV4S2Lf2hYmZQ3Qf4t/YyyBaJNuxLPyjzvDma0zPp/M=", + "lastModified": 1757545623, + "narHash": "sha256-mCxPABZ6jRjUQx3bPP4vjA68ETbPLNz9V2pk9tO7pRQ=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "f01fe91b0108a7aff99c99f2e9abbc45db0adc2a", + "rev": "8cd5ce828d5d1d16feff37340171a98fc3bf6526", "type": "github" }, "original": { @@ -571,11 +571,11 @@ }, "nixpkgs-lib": { "locked": { - "lastModified": 1753579242, - "narHash": "sha256-zvaMGVn14/Zz8hnp4VWT9xVnhc8vuL3TStRqwk22biA=", + "lastModified": 1754788789, + "narHash": "sha256-x2rJ+Ovzq0sCMpgfgGaaqgBSwY+LST+WbZ6TytnT9Rk=", "owner": "nix-community", "repo": "nixpkgs.lib", - "rev": "0f36c44e01a6129be94e3ade315a5883f0228a6e", + "rev": "a73b9c743612e4244d865a2fdee11865283c04e6", "type": "github" }, "original": { @@ -601,11 +601,11 @@ }, "nixpkgs-unstable": { "locked": { - "lastModified": 1752900028, - "narHash": "sha256-dPALCtmik9Wr14MGqVXm+OQcv7vhPBXcWNIOThGnB/Q=", + "lastModified": 1757584362, + "narHash": "sha256-XeTX/w16rUNUNBsfaOVCDoMMa7Xu7KvIMT7tn1zIEcg=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "6b4955211758ba47fac850c040a27f23b9b4008f", + "rev": "d33e926c80e6521a55da380a4c4c44a7462af405", "type": "github" }, "original": { @@ -664,11 +664,11 @@ }, "nixpkgs_4": { "locked": { - "lastModified": 1755186698, - "narHash": "sha256-wNO3+Ks2jZJ4nTHMuks+cxAiVBGNuEBXsT29Bz6HASo=", + "lastModified": 1757745802, + "narHash": "sha256-hLEO2TPj55KcUFUU1vgtHE9UEIOjRcH/4QbmfHNF820=", "owner": "nixos", "repo": "nixpkgs", - "rev": "fbcf476f790d8a217c3eab4e12033dc4a0f6d23c", + "rev": "c23193b943c6c689d70ee98ce3128239ed9e32d1", "type": "github" }, "original": { @@ -696,11 +696,11 @@ }, "nixunstable": { "locked": { - "lastModified": 1755186698, - "narHash": "sha256-wNO3+Ks2jZJ4nTHMuks+cxAiVBGNuEBXsT29Bz6HASo=", + "lastModified": 1757745802, + "narHash": "sha256-hLEO2TPj55KcUFUU1vgtHE9UEIOjRcH/4QbmfHNF820=", "owner": "nixos", "repo": "nixpkgs", - "rev": "fbcf476f790d8a217c3eab4e12033dc4a0f6d23c", + "rev": "c23193b943c6c689d70ee98ce3128239ed9e32d1", "type": "github" }, "original": { @@ -720,11 +720,11 @@ "systems": "systems_7" }, "locked": { - "lastModified": 1755095763, - "narHash": "sha256-cFwtMaONA4uKYk/rBrmFvIAQieZxZytoprzIblTn1HA=", + "lastModified": 1758032055, + "narHash": "sha256-quoLrTtC8JVG0HEv3VzJSXiQnL40K5CX9yvYqd7OKpc=", "owner": "nix-community", "repo": "nixvim", - "rev": "ecc7880e00a2a735074243d8a664a931d73beace", + "rev": "796d662401c420ba11d34901185718059aa3bfb5", "type": "github" }, "original": { @@ -740,11 +740,11 @@ "nixpkgs": "nixpkgs_4" }, "locked": { - "lastModified": 1755452770, - "narHash": "sha256-oc8xrqvVIoDxbfTlbkE1XQ7O88TgNZn5FOZKLiuIEmg=", + "lastModified": 1758030607, + "narHash": "sha256-ph7zS5GkgIh0fvaSNbIstJEVDgkskdRIwNyfXccSTSo=", "owner": "nix-community", "repo": "NUR", - "rev": "eab62298402c7cdfdefda647a4046befa3a84051", + "rev": "f534dee3dc628ceb5b036b174363c1196df5a529", "type": "github" }, "original": { @@ -763,11 +763,11 @@ ] }, "locked": { - "lastModified": 1754301638, - "narHash": "sha256-aRgzcPDd2axHFOuMlPLuzmDptUM2JU8mUL3jfgbBeyc=", + "lastModified": 1757885130, + "narHash": "sha256-56CMb5W/pgjKLh0bx2ekhn5rde/YmgR63HAqrY9/BCw=", "owner": "NuschtOS", "repo": "search", - "rev": "a60091045273484c040a91f5c229ba298f8ecc27", + "rev": "fae3c59a646e00c4b1d359c50b27458a0713d2fd", "type": "github" }, "original": { @@ -1022,11 +1022,11 @@ "nixpkgs": "nixpkgs_5" }, "locked": { - "lastModified": 1755396877, - "narHash": "sha256-92gZRDz3zEsodraI0ZxPzZrpjSqc2qjxTW9HOflzKFw=", + "lastModified": 1757987448, + "narHash": "sha256-ltDT7EIfLHV42p99HnDfDviC8jN7tcOed1qsLEFypl8=", "owner": "nix-community", "repo": "nix-vscode-extensions", - "rev": "0cf076c0bafbe7cbd33a3b7377ed24827674e8be", + "rev": "e496568b0e69d9d54c8cfef96ed1370952ad9786", "type": "github" }, "original": { @@ -1043,11 +1043,11 @@ ] }, "locked": { - "lastModified": 1755261305, - "narHash": "sha256-EOqCupB5X5WoGVHVcfOZcqy0SbKWNuY3kq+lj1wHdu8=", + "lastModified": 1757937573, + "narHash": "sha256-B+MT526k5th4x22h213/CgzdkKWIaeaa0+Y0uuCkH/I=", "owner": "nix-community", "repo": "NixOS-WSL", - "rev": "203a7b463f307c60026136dd1191d9001c43457f", + "rev": "134e117c969f42277f1c5e60c8fbcac103c2c454", "type": "github" }, "original": { diff --git a/home/baseline/shell.nix b/home/baseline/shell.nix index 0126e07..c1920df 100644 --- a/home/baseline/shell.nix +++ b/home/baseline/shell.nix @@ -25,13 +25,13 @@ nixup = "nix flake lock update"; nixcopy = "nix copy --to \"s3://binary-cache/?profile=default&endpoint=nas.home%3A9000&scheme=http\""; r = "run0"; - s = "nix run \".#runserver\""; updateScript = "nix-shell maintainers/scripts/update.nix --argstr package"; # General k = "kubectl"; kn = "kubectl get nodes -o wide"; kp = "kubectl get pods -o wide"; + s = "lazyssh"; win = "sudo virsh start win10"; yaml2js = "python -c 'import sys, yaml, json; json.dump(yaml.load(sys.stdin), sys.stdout, indent=4)'"; z = "zeditor ."; diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index fa54b02..dee199c 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -4,10 +4,10 @@ with pkgs; [ dig - dnsutils jqp kubernetes-helm iamb + lazyssh rainfrog tenere wiki-tui From e6d4bf0cdf5ea8bfc0309daeb3afbad20c9cd4e7 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 16 Sep 2025 09:52:12 -0500 Subject: [PATCH 110/124] Fix SSH config for new module --- home/baseline/ssh.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/home/baseline/ssh.nix b/home/baseline/ssh.nix index c2c79df..bcc607e 100644 --- a/home/baseline/ssh.nix +++ b/home/baseline/ssh.nix @@ -9,7 +9,6 @@ }; programs.ssh = { enable = true; - serverAliveInterval = 60; includes = [ "config.local" ]; @@ -27,6 +26,7 @@ "*" = { dynamicForwards = [ { port = 10240; } ]; + serverAliveInterval = 60; extraOptions.LogLevel = "error"; }; From 54d61606d133f705690c3b54c9f0edc1fbd0be6e Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 16 Sep 2025 09:52:23 -0500 Subject: [PATCH 111/124] Update IVR stuff --- darwin/hosts/ivr/default.nix | 2 -- home/hosts/ivr/default.nix | 12 ++++++++++++ 2 files changed, 12 insertions(+), 2 deletions(-) diff --git a/darwin/hosts/ivr/default.nix b/darwin/hosts/ivr/default.nix index 4cad7cd..8cbf603 100644 --- a/darwin/hosts/ivr/default.nix +++ b/darwin/hosts/ivr/default.nix @@ -21,7 +21,6 @@ in name = "libvirt"; restart_service = true; } - "mysql" "nushell" "poetry" { @@ -42,7 +41,6 @@ in "ghostty" "firefox" "microsoft-teams" - "mysqlworkbench" "notunes" "onlyoffice" "pgadmin4" diff --git a/home/hosts/ivr/default.nix b/home/hosts/ivr/default.nix index 41d76e1..c7cd6d9 100644 --- a/home/hosts/ivr/default.nix +++ b/home/hosts/ivr/default.nix @@ -81,6 +81,18 @@ in }; }; }; + ssh.matchBlocks = lib.listToAttrs (lib.map (key: { name = "${key}.ivrtechnology.com"; value = {}; }) [ + "apidev1" + "asdev1" + "agidev1" + "kdev1" + "kdev2" + "kdev3" + "webdev4" + "webdev5" + + "web4" + ]); tmux.shell = (lib.getExe x); }; } From 5476a4fb563fdcd0cb8ce1e3314bffbe4697aecc Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 16 Sep 2025 22:35:53 -0400 Subject: [PATCH 112/124] Add mariadb tools to nix-darwin --- home/hosts/ivr/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/home/hosts/ivr/default.nix b/home/hosts/ivr/default.nix index c7cd6d9..3fab2b0 100644 --- a/home/hosts/ivr/default.nix +++ b/home/hosts/ivr/default.nix @@ -36,6 +36,7 @@ in just k9s kubectl + mariadb minikube mise nil From 8847d92b2c20e0bca3f53f8764f45b314732f17e Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sun, 21 Sep 2025 18:51:35 -0500 Subject: [PATCH 113/124] Update flake.nix --- flake.nix | 1 + home/baseline/ssh.nix | 1 + modules/hm/gui.nix | 3 ++- 3 files changed, 4 insertions(+), 1 deletion(-) diff --git a/flake.nix b/flake.nix index 5654219..231bffa 100644 --- a/flake.nix +++ b/flake.nix @@ -79,6 +79,7 @@ packages_overlay top.nurpkgs.overlays.default top.vsext.overlays.default + top.nixvimunstable.overlays.default ]; in diff --git a/home/baseline/ssh.nix b/home/baseline/ssh.nix index bcc607e..0510bfe 100644 --- a/home/baseline/ssh.nix +++ b/home/baseline/ssh.nix @@ -11,6 +11,7 @@ enable = true; includes = [ "config.local" ]; + enableDefaultConfig = false; matchBlocks = let diff --git a/modules/hm/gui.nix b/modules/hm/gui.nix index 7df5422..86c3759 100644 --- a/modules/hm/gui.nix +++ b/modules/hm/gui.nix @@ -49,7 +49,8 @@ in [ bitwarden endeavour - jellyfin-media-player + # Is removed because it depends on qt5-qtwebengine + # jellyfin-media-player nextcloud-client slack (pkgs.zoom-us.overrideAttrs { From 869208556c858eab90851be4dd9f127c36a5119c Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sun, 21 Sep 2025 18:52:45 -0500 Subject: [PATCH 114/124] Fix up some vim config foibles --- home/baseline/vim/config.nix | 1 - home/baseline/vim/default.nix | 18 ++++++++++++++---- 2 files changed, 14 insertions(+), 5 deletions(-) diff --git a/home/baseline/vim/config.nix b/home/baseline/vim/config.nix index 80369e0..a22f0a1 100644 --- a/home/baseline/vim/config.nix +++ b/home/baseline/vim/config.nix @@ -150,7 +150,6 @@ extraConfigVim = builtins.readFile ./extra.vimrc; extraPlugins = with pkgs.vimPlugins; [ bufexplorer - context-vim vim-indent-guides ]; diff --git a/home/baseline/vim/default.nix b/home/baseline/vim/default.nix index 8a2f332..a04ba67 100644 --- a/home/baseline/vim/default.nix +++ b/home/baseline/vim/default.nix @@ -1,7 +1,8 @@ { config, - pkgs, lib, + nixvim, + pkgs, ... }: @@ -10,7 +11,16 @@ fonts.fontconfig.enable = true; home.packages = with pkgs.nerd-fonts; [ hack ]; - programs.nixvim = (import ./config.nix { inherit config pkgs lib; }) // { - enable = true; - }; + programs.nixvim = + (import ./config.nix { + inherit + config + nixvim + pkgs + lib + ; + }) + // { + enable = true; + }; } From 17601803eeb5c7321bff64830b75882ae5265f3e Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sun, 21 Sep 2025 18:53:25 -0500 Subject: [PATCH 115/124] Add nas1 DNS settings --- hosts/genesis/net/hosts | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hosts/genesis/net/hosts b/hosts/genesis/net/hosts index da17425..2c15ae3 100644 --- a/hosts/genesis/net/hosts +++ b/hosts/genesis/net/hosts @@ -17,6 +17,7 @@ # 11 - old jude 10.42.1.12 tv 10.42.1.13 zeke zeke.thehellings.lan +10.42.1.14 nas1 nas1.thehellings.lan # VMs 10.42.4.1 matrix matrix.thehellings.lan @@ -28,6 +29,7 @@ # IPMI 10.42.100.6 isaiahbmc isaiahbmc.thehellings.lan +10.42.100.14 nas1bmc nas1bmc.thehellings.lan # Tailscale hosts 100.119.228.115 chronicles.home nas.home chronicles.shire-zebra.ts.net From c62433f8350a69b3931aad92cd00d39b6e14a5ea Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sun, 21 Sep 2025 18:53:42 -0500 Subject: [PATCH 116/124] Make rebuild more responsive --- home/baseline/nushell/functions.nu | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/home/baseline/nushell/functions.nu b/home/baseline/nushell/functions.nu index 7619fe4..b1c3ae8 100644 --- a/home/baseline/nushell/functions.nu +++ b/home/baseline/nushell/functions.nu @@ -1,3 +1,4 @@ +# vim: set filetype=nushell : let servers = [isaiah jeremiah zeke genesis vm-gitlab vm-jellyfin] def par-map [ items: list, c: closure ] { @@ -16,11 +17,13 @@ def rebuild [] { sudo darwin-rebuild switch } else { let hostname = uname | get nodename - let build = ^nom build $"/etc/nixos#nixosConfigurations.($hostname).config.system.build.toplevel" | complete - if build.exit_code == 0 { - nvd diff /run/current-system result - sudo nixos-rebuild switch - } + let build = ^nom build $"/etc/nixos#nixosConfigurations.($hostname).config.system.build.toplevel" + if $env.LAST_EXIT_CODE == 0 { + nvd diff /run/current-system result + run0 nixos-rebuild switch + } else { + print "Error during build" + } } } From 774b34cc49b3d67c31ea2969bf5a82b81e32627c Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 22 Sep 2025 08:57:47 -0500 Subject: [PATCH 117/124] Remove docker from IVR and add uv --- darwin/hosts/ivr/default.nix | 7 ------- home/baseline/tools.nix | 1 + 2 files changed, 1 insertion(+), 7 deletions(-) diff --git a/darwin/hosts/ivr/default.nix b/darwin/hosts/ivr/default.nix index 8cbf603..5d496d2 100644 --- a/darwin/hosts/ivr/default.nix +++ b/darwin/hosts/ivr/default.nix @@ -11,12 +11,7 @@ in enable = true; brews = [ "bitwarden-cli" - { - name = "colima"; - restart_service = true; - } "direnv" - "docker-compose" { name = "libvirt"; restart_service = true; @@ -37,7 +32,6 @@ in "bruno" "chromium" "dbeaver-community" - "docker" "ghostty" "firefox" "microsoft-teams" @@ -46,7 +40,6 @@ in "pgadmin4" "podman-desktop" "tabby" - "twine" "vagrant" "virtualbox" "visual-studio-code" diff --git a/home/baseline/tools.nix b/home/baseline/tools.nix index dee199c..59ea497 100644 --- a/home/baseline/tools.nix +++ b/home/baseline/tools.nix @@ -10,6 +10,7 @@ lazyssh rainfrog tenere + uv wiki-tui ] ++ (lib.optionals pkgs.stdenv.hostPlatform.isLinux [ From eeb719e6b506ef72edb8be31f1936fc09563a09e Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 23 Sep 2025 11:30:38 -0500 Subject: [PATCH 118/124] Fix Ghostty on SSH --- home/baseline/ssh.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/home/baseline/ssh.nix b/home/baseline/ssh.nix index 0510bfe..6a6a611 100644 --- a/home/baseline/ssh.nix +++ b/home/baseline/ssh.nix @@ -28,7 +28,10 @@ "*" = { dynamicForwards = [ { port = 10240; } ]; serverAliveInterval = 60; - extraOptions.LogLevel = "error"; + extraOptions = { + LogLevel = "error"; + SetEnv = "TERM=xterm-256color"; + }; }; "10.42.1.4" = lib.hm.dag.entryBefore [ "10.42.*" ] nas; From c2eedbfeb985fb90513e71a012bbe15b80145f02 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sat, 27 Sep 2025 00:40:45 -0500 Subject: [PATCH 119/124] Add bookmarks --- modules/hm/gui/bookmarks.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/modules/hm/gui/bookmarks.nix b/modules/hm/gui/bookmarks.nix index abeba7c..87e7f98 100644 --- a/modules/hm/gui/bookmarks.nix +++ b/modules/hm/gui/bookmarks.nix @@ -232,6 +232,14 @@ name = "Syncthing - nas"; url = "http://nas.home:8384/#"; } + { + name = "Pinchflat"; + url = "http://nas1.shire-zebra.ts.net:8945"; + } + { + name = "Portainer"; + url = "http://nas1.shire-zebra.ts.net:31015"; + } ]; } { From b65e5a9a106c6e72cf1494f0d78fa9cdd168df7b Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sat, 27 Sep 2025 00:46:43 -0500 Subject: [PATCH 120/124] Fix long standing Zed syntax errors --- modules/hm/zed.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/modules/hm/zed.nix b/modules/hm/zed.nix index bebe8a5..3063356 100644 --- a/modules/hm/zed.nix +++ b/modules/hm/zed.nix @@ -46,10 +46,10 @@ in installRemoteServer = true; userKeymaps = [ { - context = "Editor && (showing_completions || showing code actions)"; + context = "Editor && (showing_completions || showing_code_actions)"; bindings = { enter = "editor::Newline"; - escape = "editor:Cancel"; + escape = "editor::Cancel"; }; } ]; From 16ae794239883ea39fa734aba58e076a308c3e9a Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sat, 27 Sep 2025 01:48:01 -0500 Subject: [PATCH 121/124] Add nas1 Tailscale settings --- hosts/genesis/net/hosts | 1 + 1 file changed, 1 insertion(+) diff --git a/hosts/genesis/net/hosts b/hosts/genesis/net/hosts index 2c15ae3..a8d4642 100644 --- a/hosts/genesis/net/hosts +++ b/hosts/genesis/net/hosts @@ -44,6 +44,7 @@ 100.115.57.8 linode.home 100.65.5.38 matrix.home matrix.shire-zebra.ts.net 100.127.55.22 jellyfin.home +100.114.187.61 nas1.home nas1.shire-zebra.ts.net # Dev hosts 10.42.101.1 icdm.lan wiki.icdm.lan *.icdm.lan From ddd47a24dd60cd018700622b3f1ed70448779a3c Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sat, 27 Sep 2025 01:59:07 -0500 Subject: [PATCH 122/124] Mount NFS shares to Jellyfin --- hosts/vm-jellyfin/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/hosts/vm-jellyfin/default.nix b/hosts/vm-jellyfin/default.nix index f815cef..808e5dc 100644 --- a/hosts/vm-jellyfin/default.nix +++ b/hosts/vm-jellyfin/default.nix @@ -30,17 +30,17 @@ fileSystems = { "/music" = { - device = "10.42.1.4:/volume1/music"; + device = "nas1.shire-zebra.ts.net:/mnt/all/music"; fsType = "nfs"; options = [ "ro" ]; }; "/photo" = { - device = "10.42.1.4:/volume1/photo"; + device = "nas1.shire-zebra.ts.net:/mnt/all/photos"; fsType = "nfs"; options = [ "ro" ]; }; "/video" = { - device = "10.42.1.4:/volume1/video/"; + device = "nas1.shire-zebra.ts.net:/mnt/all/video/"; fsType = "nfs"; options = [ "ro" ]; }; From 7951863c6e33a61985e6a5877374b7988cf3841d Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sat, 27 Sep 2025 09:19:17 -0500 Subject: [PATCH 123/124] Do not build on Genesis --- home/baseline/nushell/functions.nu | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/home/baseline/nushell/functions.nu b/home/baseline/nushell/functions.nu index b1c3ae8..75fadd2 100644 --- a/home/baseline/nushell/functions.nu +++ b/home/baseline/nushell/functions.nu @@ -32,7 +32,7 @@ def deploy [ $host: string, $build: string = "" ] { if $build == "" { $buildhost = $host } - if $buildhost == "linode" { + if $buildhost == "linode" or $buildhost == "genesis" { $buildhost = "isaiah" } nixos-rebuild switch --sudo --use-substitutes --target-host $host --build-host $buildhost From 4ddfc64f268b43c16f825a60dba4bf2c938fa0e0 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sat, 27 Sep 2025 09:20:01 -0500 Subject: [PATCH 124/124] Remove Dashy --- hosts/genesis/default.nix | 99 +-------------------------------------- 1 file changed, 1 insertion(+), 98 deletions(-) diff --git a/hosts/genesis/default.nix b/hosts/genesis/default.nix index 209e6e2..c1ae1f3 100644 --- a/hosts/genesis/default.nix +++ b/hosts/genesis/default.nix @@ -2,10 +2,9 @@ # your system. Help is available in the configuration.nix(5) man page # and in the NixOS manual (accessible by running ‘nixos-help’). -{ config, pkgs, ... }: +{ pkgs, ... }: let - dashy_port = "8080"; speedtest_port = "19472"; in { @@ -22,7 +21,6 @@ in proxies = { "speed.home".target = "http://localhost:${speedtest_port}"; "speedtest.thehellings.lan".target = "http://localhost:${speedtest_port}"; - "dashy.home".target = "http://localhost:${dashy_port}"; }; }; @@ -41,102 +39,7 @@ in networking.hostName = "genesis"; # Define your hostname. - services = { - dashy = { - enable = true; - settings = { - appConfig = { - enableFontAwesome = true; - statusCheck = true; - statusCheckInterval = 20; - theme = "callisto"; - }; - pageInfo = { - description = "Hellings Lab"; - navLinks = [ - { - path = "/"; - title = "Home"; - } - { - path = "http://speed.home"; - title = "Local Speedtest"; - } - ]; - }; - sections = [ - { - name = "Hosting"; - displayData = { - sortBy = "alphabetical"; - rows = 1; - cols = 1; - collapsed = false; - hideForGusts = false; - }; - items = [ - { - title = "Romans"; - description = "Core Proxmox"; - icon = "favicon"; - url = "https://10.42.1.1:8006"; - target = "newtab"; - statusCheckAllowInsecure = true; - } - { - title = "Isaiah"; - description = "Isaiah Proxmox"; - icon = "favicon"; - url = "https://isaiah.thehellings.lan:8006"; - target = "newtab"; - statusCheckAllowInsecure = true; - } - { - title = "Linode"; - icon = "favicon"; - url = "https://login.linode.com/login"; - target = "newtab"; - } - ]; - } - { - name = "Services"; - displayData = { - sortBy = "alphabetical"; - rows = 1; - cols = 1; - collapsed = false; - hideForGusts = false; - }; - items = [ - { - title = "Jellyfin"; - description = "Home Jellyfin Server"; - icon = "favicon"; - url = "http://jellyfin.home"; - target = "newtab"; - } - { - title = "Speedtest"; - description = "Local Speedtest"; - icon = "favicon"; - url = "http://speed.home"; - target = "newtab"; - } - ]; - } - ]; - }; - }; - }; - virtualisation.oci-containers.containers = { - dashy = { - image = "lissy93/dashy:latest"; - hostname = "dashy"; - ports = [ "${dashy_port}:${dashy_port}" ]; - volumes = [ "${config.services.dashy.finalDrv}/conf.yml:/app/user-data/conf.yml" ]; - }; speedtest = { image = "ghcr.io/librespeed/speedtest"; hostname = "speedtest";